Release date:
2026-09-15 09:01:54 UTC
Description:
- CVE-2026-86138: add integer-overflow checks to the pool size calculation in
xmlDictAddQString and cap the QName length in xmlDictQLookup to prevent a
heap buffer overflow
Updated packages:
-
libxml2-2.9.1-6.amzn2.5.26.tuxcare.els2.i686.rpm
sha:3f902793d9f1fd07db5944e3769956199c03865a9719f9d0188a0aa19aa67b03
-
libxml2-2.9.1-6.amzn2.5.26.tuxcare.els2.x86_64.rpm
sha:ae9cbb6847556a2cfa1f51f211338f5e231212777434d29d7a82d1d6a2404522
-
libxml2-devel-2.9.1-6.amzn2.5.26.tuxcare.els2.x86_64.rpm
sha:80e77e9e34bee3b3d9d9412fbe901232f0537313f6a6c231feadcba7a1179f86
-
libxml2-python-2.9.1-6.amzn2.5.26.tuxcare.els2.x86_64.rpm
sha:5b5d92afcdda2f09e9fab3e0d051ce6d154d2efa6b2a6bac2887744b4db24686
-
libxml2-static-2.9.1-6.amzn2.5.26.tuxcare.els2.x86_64.rpm
sha:bb0fd1ab0e3b08a20d1e3ea496de59f01841edad3504fbc69e6417735f3b2b89
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.