Release date:
2026-09-17 10:57:35 UTC
Description:
- CVE-2024-56171: use-after-free after xmlSchemaItemListAdd in the XML Schema
identity-constraint code (xmlSchemaIDCFillNodeTables,
xmlSchemaBubbleIDCNodeTables)
- CVE-2026-6653: use-after-free in xmlParseInternalSubset; xmlPushInput()
returned -1 for a parameter entity input it had already pushed, so the caller
freed an input stream that ctxt->input still pointed at. Reachable through the
entity amplification check carried by 2.10.2 for CVE-2021-3541, which this
keeps in place. Also guards the xmlSkipBlankChars() loop on XML_PARSER_EOF
(upstream e129c1d1), without which the same document spins at 100% CPU once
the input is no longer freed
Updated packages:
-
alt-libxml2-2.10.2-7.el8.x86_64.rpm
sha:37587ce5eec41700b7d11710e576f8e4884eec342e0b404a9421534a9d943b23
-
alt-libxml2-devel-2.10.2-7.el8.x86_64.rpm
sha:228925dc889b3d7c22690ead45b666782e1df130661c481508317c67e0e5bfe5
-
alt-libxml2-static-2.10.2-7.el8.x86_64.rpm
sha:0f7aaa7bc29e6c08243a81f159abcab00729f26bbf78f6aca0d784d8269f2f25
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.