[CLSA-2026:1789481020] alt-libxml2: Fix of 8 CVEs
Type:
security
Severity:
Critical
Release date:
2026-09-15 14:03:57 UTC
Description:
- CVE-2026-86137: out-of-bounds read in the NXT macro in xmlFAParsePosCharGroup - CVE-2026-86138: integer overflow and heap buffer overflow in xmlDictAddQString - CVE-2025-24928: stale-length bounds check inside the xmlSnprintfElements loop (upstream 8c8753ad); this is the stack overflow reachable on 2.10.2 - CVE-2026-86140: unchecked strcat at the entry and exit of xmlSnprintfElements (upstream d1686f91); hardening only on 2.10.2, callers pass an emptied buffer - CVE-2026-86141: NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure - CVE-2026-86142: heap buffer overflow in xmlXPtrEvalXPtrPart from xpointer length saturation - CVE-2026-86143: negative lengths reaching write callbacks in xmlIO - CVE-2026-86144: xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags; the include context now inherits every document parse flag (NOENT, RECOVER and HUGE included), not only NONET
Updated packages:
  • alt-libxml2-2.10.2-6.el10.x86_64.rpm
    sha:8c95dad3cdd0387fb6a460cae38b69b3f2f2d210ac93df6f046bba8e94bf3aa3
  • alt-libxml2-devel-2.10.2-6.el10.x86_64.rpm
    sha:4d8ad8c40d0de687bbe1646fbcc02361025edb2d995a545e53408a103a8824b8
  • alt-libxml2-static-2.10.2-6.el10.x86_64.rpm
    sha:14897b8ba32aa187f4ee97e40515e7974fbb0b5df48087ce573b9c22b41073c5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.