[CLSA-2026:1789395150] expat: Fix of CVE-2026-76957
Type:
security
Severity:
Critical
Release date:
2026-09-16 23:32:32 UTC
Description:
- CVE-2026-76957: fix a use-after-free by covering the custom XML_Encoding convert/release callbacks with the handler call-depth tracking, so a same-parser call made from inside them is rejected
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els7.i686.rpm
    sha:d51b91272797e67458f9defb1a5538684e46a1dc83ea0bf08a963fe27a289693
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els7.x86_64.rpm
    sha:9a37a1b28a14b56465d90282b8b0d5925e6083dd5ac02ac4e3fabbb811e2a8f4
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els7.i686.rpm
    sha:77c194867e26fd7b7b71f29f633176a7a2a15844c3fd2525804f712fe0d22659
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els7.x86_64.rpm
    sha:fc833a69c3e751ad397ce620bc7d4a754ebc98736f299f2e4eb3a4b66849e97e
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els7.i686.rpm
    sha:d95aa96126ad74b6744ccd26e22f646501bb0eb08f40d349bcb47d05ccc55228
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els7.x86_64.rpm
    sha:4721e77369fe202916ad74df86427223c185971a62edebed586ee66a186fcf17
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.