[CLSA-2026:1789202718] expat: Fix of CVE-2026-76957
Type:
security
Severity:
Critical
Release date:
2026-09-12 08:45:30 UTC
Description:
- CVE-2026-76957: fix use-after-free from calling XML_ParserFree() inside a custom unknown-encoding convert or release callback, by routing both through callUnknownEncodingConvert()/callUnknownEncodingRelease() in handleUnknownEncoding() so they are bracketed by the handler call depth tracking added for CVE-2026-56131
CVEs fixed:
Updated packages:
  • expat-2.5.0-1.el8.tuxcare.els7.i686.rpm
    sha:26b774e634a07f3973cd72c8ce49141545afe38571f03e1f6f993ae46c20e1ae
  • expat-2.5.0-1.el8.tuxcare.els7.x86_64.rpm
    sha:d41a095f275c4a5e634ae6faad29d53700a21e82e4fc29d9e7633f67a657c33c
  • expat-devel-2.5.0-1.el8.tuxcare.els7.i686.rpm
    sha:c69527525473508d8ee677575ca0e63be9a202a069f3e9158f3ee25c8640569e
  • expat-devel-2.5.0-1.el8.tuxcare.els7.x86_64.rpm
    sha:3605e61cc5218b7165caa4237afb87f0fcbd4f03104401eedaf4ec675e5fa5f1
  • expat-static-2.5.0-1.el8.tuxcare.els7.x86_64.rpm
    sha:5cf669781662b7186b72188cf6628a1f02340fa88f34f89c0f3cc4c18fb0c043
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.