Release date:
2026-09-16 10:25:27 UTC
Description:
- CVE-2026-86143: guard the size_t buffer length against INT_MAX before it is
narrowed to the int passed to writecallback in xmlOutputBufferWrite(),
xmlOutputBufferWriteEscape() and xmlOutputBufferFlush() (xmlIO.c), so a
negative length can no longer reach an output callback
- CVE-2026-86144: propagate the document's parseFlags in xmlXIncludeProcess()
and xmlXIncludeProcessTree() and apply them to the parse="text" sub-context
in xmlXIncludeLoadTxt() (xinclude.c), so XML_PARSE_NONET is honoured during
XInclude resolution
Updated packages:
-
libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
sha:4e84888d250e0cb81c628d569aed65dccbff3737441a6429b54c8357e8796f26
-
libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
sha:97573fb81f7d52f8942f5ff35510bbd32f74db692d6e2ed2455ffb337d51693a
-
libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
sha:37a295a9f71dda9b717bb023c0d73c601997e0ceb26be95089fc3764ba9bbcb1
-
libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
sha:5cb5daaadcdc9636f0ffe22bbf449014a2bf257916dbdd224b3854b8fe060097
-
libxml2-python-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
sha:43b854aa24becb1b1237407aa1816709122e48ccb32ee28cc48ffeaa8d615583
-
libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els10.i686.rpm
sha:e5a124bdc10f74c30c3fc1b05e9c4d263b9f152069e29bdc9c4aff616942cf66
-
libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els10.x86_64.rpm
sha:252b0bb89c0f1639ecebc898ef5e19eee984e8148bc04d7babf679eba164bc92
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.