[CLSA-2026:1788950367] expat: Fix of CVE-2026-56131
Type:
security
Severity:
Critical
Release date:
2026-09-09 10:39:39 UTC
Description:
- CVE-2026-56131: fix a use-after-free by refusing re-entrant XML_ResumeParser calls issued from inside handler callbacks; carries the prerequisite handler call-depth tracking, which also covers CVE-2026-50219 and CVE-2026-56412
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els6.i686.rpm
    sha:8c1276bfd0d3da32799424994390f8855f43383c00f853cc7c46e34eeb20056a
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els6.x86_64.rpm
    sha:77a06e389315731f83d451ff8c063b363749392e82d62a7b9865dfdf20f988d4
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els6.i686.rpm
    sha:909cc743ed21d38d0948ae658e9051bca0649bd97801aa42977162d4764aabea
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els6.x86_64.rpm
    sha:08677848bcf9ac5cdcf7adccd02d7c3a3a9dcebef34c1120e611dc0957c5c05d
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els6.i686.rpm
    sha:0c16715a7699d9acbe8a641bb33c288a266a83bf7947ac1d401d803e93603f48
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els6.x86_64.rpm
    sha:65e7cf180471e63925477ba042dcf230bf231e9a86c6158543ec0d7c37f5dd3d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.