[CLSA-2026:1788949837] expat: Fix of CVE-2026-56131
Type:
security
Severity:
Critical
Release date:
2026-09-09 11:21:08 UTC
Description:
- CVE-2026-56131: fix a use-after-free by refusing re-entrant XML_ResumeParser calls issued from inside handler callbacks; carries the prerequisite handler call-depth tracking, which also covers CVE-2026-50219 and CVE-2026-56412
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els6.i686.rpm
    sha:c70c31ab3a72b40143823f949d12174523a25ec329879c6f7efe2bd7faa6e845
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els6.x86_64.rpm
    sha:8d8acb8c2bed62bd7cd6df6e00a1cc478e5021cc87974d0d526de9e44530a192
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els6.i686.rpm
    sha:6f5927d0e3d2974606e71fe870ad5c6a78c2014c9bd0bc688fc364af5ed1446f
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els6.x86_64.rpm
    sha:d2c0266c33f5393aaffde3767ceaf8d99392da84a8c058f59179be157eb8e01d
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els6.i686.rpm
    sha:78364925e5154dce7b4ba06a2cf3cb0d48e010f0aaedcf1f1c9bf9663f3e3ec4
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els6.x86_64.rpm
    sha:c8fdefa3d23c5fe63f6e78887a7fe6466f0e7630354bd543affeb4fe89b38605
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.