[CLSA-2026:1789395602] expat: Fix of CVE-2026-76957
Type:
security
Severity:
Critical
Release date:
2026-09-15 14:45:40 UTC
Description:
- CVE-2026-76957: fix a use-after-free by covering the custom XML_Encoding convert/release callbacks with the handler call-depth tracking, so a same-parser call made from inside them is rejected
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els7.i686.rpm
    sha:5b5f7a71026873c07ee3ec9f4c392475a4825f6b30b51c150285e135e851c0d7
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els7.x86_64.rpm
    sha:18f45fa9865160c5a61ee6ae0eb1577c0aa2cdcd4f56362153b9d88ddd8b57e9
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els7.i686.rpm
    sha:638bf379fe2d822aad7f8a225a3816ae69bd18a769fb077af808ab27b030ff9b
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els7.x86_64.rpm
    sha:216bcd63f2a78c9570c468f0f801e4c1d0a89c23c3a8075fbf6174ef6cff4c4f
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els7.i686.rpm
    sha:e4d0c751ee17ba46934baca08cdfdd63cc9c6a7cb237bd397008912cd7128e43
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els7.x86_64.rpm
    sha:e7fbd8969cddb1d3d5ff272d7ccc74e26dd017450ee32ac35d65abff33986744
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.