Release date:
2026-09-17 00:33:23 UTC
Description:
- CVE-2026-86143: guard the size_t buffer length against INT_MAX before it is
narrowed to the int passed to writecallback in xmlOutputBufferWrite(),
xmlOutputBufferWriteEscape() and xmlOutputBufferFlush() (xmlIO.c), so a
negative length can no longer reach an output callback
- CVE-2026-86144: propagate the document's parseFlags in xmlXIncludeProcess()
and xmlXIncludeProcessTree() and apply them to the parse="text" sub-context
in xmlXIncludeLoadTxt() (xinclude.c), so XML_PARSE_NONET is honoured during
XInclude resolution
Updated packages:
-
libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
sha:53e6d4167afb994608e6e7ba9647746781350612fd93d006da9f97bd5a502b8a
-
libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
sha:73138fb62890de4656b1935f3ec3909d70bac622cfdcd843a134c77df4da5e99
-
libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
sha:c7e48b0b9361c951d6a6c2770eb4727c7090dcdea7ed81c963b32ee30a11b1b2
-
libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
sha:da89260de80e27b894acda117bfa64c679c44f26d22c290d453764e4b37d3b1d
-
libxml2-python-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
sha:908f3d64354a4babaf9ffb3b03245f5cc1925e54f35b2fb377e80cc1d6990f71
-
libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
sha:37e36670607bbde63274c166ddeaa7ded53a0ece64978668e981c0b0aa97c113
-
libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
sha:9cfa2855f4056edf64532773be157690aaf40fc72cc538b2db94322e9855fa1c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.