[CLSA-2026:1789658144] libxml2: Fix of CVE-2026-86138
Type:
security
Severity:
Critical
Release date:
2026-09-17 15:15:55 UTC
Description:
- CVE-2026-86138: add overflow checks to xmlDictAddQString pool size calculation and reject over-long QNames in xmlDictQLookup to prevent heap buffer overflow when interning long QNames
CVEs fixed:
Updated packages:
  • libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els11.i686.rpm
    sha:cd56f7b8ae7f9b94f981ead677497ce8ffbd7ebdc4ccdd2ec238fe8dbd541c68
  • libxml2-2.9.1-6.0.11.el7_9.6.tuxcare.els11.x86_64.rpm
    sha:53fd54b80b82daf1e59046639b38da45d28b6d3885d62d5fe78ba1adc85203fc
  • libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els11.i686.rpm
    sha:c23539509d62cc31de443c79e3c60e23d6e51e8f20c9e5b37ea69b2b014ba532
  • libxml2-devel-2.9.1-6.0.11.el7_9.6.tuxcare.els11.x86_64.rpm
    sha:e55e968d13faea499de1748b3996a0ae8caaaa47e75a44daae8c7a87be1287ef
  • libxml2-python-2.9.1-6.0.11.el7_9.6.tuxcare.els11.x86_64.rpm
    sha:8d16ade345331ff81b3e00f447bd9a336f3ad7b5b2d1887d05ffa379e127ada8
  • libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els11.i686.rpm
    sha:008b25e6d7e667a7ec8549f4987e0dd1a17206169c82526defa5e5af2aedfc2e
  • libxml2-static-2.9.1-6.0.11.el7_9.6.tuxcare.els11.x86_64.rpm
    sha:eaa553965764d695b3eb586deee09c9b27f7075e830b38d69dad8566b1ab001e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.