[CLSA-2026:1789396456] expat: Fix of CVE-2026-76957
Type:
security
Severity:
Critical
Release date:
2026-09-14 14:34:29 UTC
Description:
- CVE-2026-76957: fix use-after-free from calling XML_ParserFree() inside a custom unknown-encoding convert or release callback, by routing both through callUnknownEncodingConvert()/callUnknownEncodingRelease() so they are covered by the handler call depth tracking
CVEs fixed:
Updated packages:
  • expat-2.0.1-13.el6_8.tuxcare.els13.i686.rpm
    sha:f5e758c90d36da6b96454c42fccfb7ed209204e29efc79f9a1b48b4c007c874d
  • expat-2.0.1-13.el6_8.tuxcare.els13.x86_64.rpm
    sha:88698761c0cb85eac448d84af0e9d6b1622de20d00133cafd2774c07e8a68399
  • expat-devel-2.0.1-13.el6_8.tuxcare.els13.i686.rpm
    sha:c4cf033560368d25a9c6b795ac7ed99ef75a958a3177face153023ce82cded8e
  • expat-devel-2.0.1-13.el6_8.tuxcare.els13.x86_64.rpm
    sha:699b216f32710b8a44113e39109f6e677fde8a9333a7f7940843024fa0d83dc3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.