[CLSA-2026:1788955237] expat: Fix of CVE-2026-56131
Type:
security
Severity:
Critical
Release date:
2026-09-09 12:00:48 UTC
Description:
- CVE-2026-56131: fix a use-after-free by refusing re-entrant XML_ResumeParser calls issued from inside handler callbacks; carries the prerequisite handler call-depth tracking, which also covers CVE-2026-50219 and CVE-2026-56412
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.amzn2.tuxcare.els6.i686.rpm
    sha:58db69a409800543df3c2b8e6ad990bef51b33bc6b70ab78860b76ea531d04b2
  • expat-2.1.0-15.0.7.amzn2.tuxcare.els6.x86_64.rpm
    sha:005fb0383a753331969b7fe540c47b26c103ab644384002ed6b235f0c83a96e0
  • expat-devel-2.1.0-15.0.7.amzn2.tuxcare.els6.x86_64.rpm
    sha:37a189fc640f4df89606e27a7fe7fa402338012f9590ccd62f8b0647d71dd613
  • expat-static-2.1.0-15.0.7.amzn2.tuxcare.els6.x86_64.rpm
    sha:b1a05b8e4da5003820b093f0828f100e608c343aeb7ddb6bf9b5be400b8da45e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.