Release date:
2026-09-16 10:29:16 UTC
Description:
- CVE-2026-86143: guard the size_t buffer length against INT_MAX before it is
narrowed to the int passed to writecallback in xmlOutputBufferWrite(),
xmlOutputBufferWriteEscape() and xmlOutputBufferFlush() (xmlIO.c), so a
negative length can no longer reach an output callback
- CVE-2026-86144: propagate the document's parseFlags in xmlXIncludeProcess()
and xmlXIncludeProcessTree() and apply them to the parse="text" sub-context
in xmlXIncludeLoadTxt() (xinclude.c), so XML_PARSE_NONET is honoured during
XInclude resolution
Updated packages:
-
libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
sha:c88c00c598c325580adbf4c6828e61a52a76629e7b1ad8363be17ba6e4a549a6
-
libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
sha:5065d5d96570dffe0d23612150d0c00f41ab7a57910c96a98030c17d562349e9
-
libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
sha:6f286a91e8b6274eaa1bf1a290dc356cf78d66f4fb529ed061ad452796dcd6aa
-
libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
sha:a750fe63b24ff45b935e436a5c8e40c7656c4a64c3d44b0202bdbac19312c630
-
libxml2-python-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
sha:8b12d9daa86ad23c0436e4975191533e6500a77b058dd5d568ea1c68138bbcb0
-
libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
sha:056cd2da7c664fe04b3050ebebe06f99021fae1269fc29d8bfa7d6bced8ae644
-
libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
sha:086fde942e62fb8aaa9eaa019aef377d005ed45b882e4fa19e0e9e5270462127
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.