[CLSA-2026:1788950538] expat: Fix of CVE-2026-56131
Type:
security
Severity:
Critical
Release date:
2026-09-09 11:32:02 UTC
Description:
- CVE-2026-56131: fix a use-after-free by refusing re-entrant XML_ResumeParser calls issued from inside handler callbacks; carries the prerequisite handler call-depth tracking, which also covers CVE-2026-50219 and CVE-2026-56412
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els6.i686.rpm
    sha:62f634e693816db740b82f52963c505d096724258e2706dda5439c4c6c057bcd
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els6.x86_64.rpm
    sha:ae141fbe9acfc19181e1683d12f55408e3bb4a12c8c0164bbebadd87d3923684
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els6.i686.rpm
    sha:8f8e988db04f1aa1b591a317e9f6b061017c4a5294a32fbb7f12629f6e5723c1
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els6.x86_64.rpm
    sha:48953cb811b5a3a4ec398e3c58f6c816e317e1526e96b4f224864db24f61a487
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els6.i686.rpm
    sha:869a80935199c06fb7d68b0a859f475aabab3241fd1da3049327fa03716e27ff
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els6.x86_64.rpm
    sha:003f813ae31271b76bd4547bf9839c03dafbc7faaafa7f56e50dd9388c7dd9f1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.