[CLSA-2026:1785316608] libxml2: Fix of CVE-2026-6653
Type:
security
Severity:
Critical
Release date:
2026-07-29 09:16:59 UTC
Description:
- CVE-2026-6653: fix use-after-free in xmlParseInternalSubset; xmlPushInput reported EOF as failure after pushing, so the caller freed a live input
CVEs fixed:
Updated packages:
  • libxml2-2.9.7-18.el8.tuxcare.els11.i686.rpm
    sha:62a945ddb6e0fb3596d99882d232e7c9535152f7493f28ed9d15a11715ab1699
  • libxml2-2.9.7-18.el8.tuxcare.els11.x86_64.rpm
    sha:5784c7c1ccae5c6582ce143623d53b5caf13ff5afae1d7007b669a8c13c707ff
  • libxml2-devel-2.9.7-18.el8.tuxcare.els11.i686.rpm
    sha:452394bdb69c3537c8e80337f4dd0d1fccc1b9854ad04efc91e3b7ddf3d81aa9
  • libxml2-devel-2.9.7-18.el8.tuxcare.els11.x86_64.rpm
    sha:1e89590de389313410fe689f217cd8c60ef087daa2e2e57ed0a9c4c3b5eefeb3
  • libxml2-static-2.9.7-18.el8.tuxcare.els11.x86_64.rpm
    sha:db5b21d854cbc5dd973ad47b884709b109660f61032303590072bd1dd3ef66c5
  • python3-libxml2-2.9.7-18.el8.tuxcare.els11.x86_64.rpm
    sha:b4848bbea75190b24aac7968113436b54026662e1a93adb7f246d7cc52af8119
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.