[CLSA-2026:1789745061] libxml2: Fix of CVE-2026-86140
Type:
security
Severity:
Critical
Release date:
2026-09-18 16:29:21 UTC
Description:
- CVE-2026-86140: add bounds checks around the englobing parenthesis strcat() calls in xmlSnprintfElements to prevent stack buffer overflow when dumping long element lists
CVEs fixed:
Updated packages:
  • libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els12.i686.rpm
    sha:098cd7cea7a6ed82a7c822e2b884d7261c9e63b1056d2208ec187903db20c166
  • libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els12.x86_64.rpm
    sha:24d47e37e3b8b5b35cfa4284f0dce01c3247d8bd4a753f638e45e80a9535455e
  • libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els12.i686.rpm
    sha:9feac15fbe6dc03051e07c123d70aead27ca165ccbccb358e26cf3a2ffb9d699
  • libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els12.x86_64.rpm
    sha:cb862ee35d055d1b1bca6883b2b5420078ad426b5c594e5c7d4317526c076880
  • libxml2-python-2.9.1-6.0.11.el7_9.6.tuxcare.els12.x86_64.rpm
    sha:8e1cf3f07d192a96f7504b4a2e387a97471e1d998588752628062dbf08e633bc
  • libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els12.i686.rpm
    sha:ea0fec32a41535d7917fa9426d9d65d6b6372a780e8ccf2c8bf5f086c1df1aa6
  • libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els12.x86_64.rpm
    sha:4d2d80db36ad1acc36552771d5b15548c08c6b91bf488d0090ccbf4a6f20ed61
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.