[CLSA-2026:1784291449] expat: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-07-17 12:31:14 UTC
Description:
- CVE-2026-50219: reject libexpat API re-entry from inside handler callbacks to prevent use-after-free - CVE-2026-56131: extend the handler re-entrancy guard to XML_ResumeParser - CVE-2026-56412: guard XML_TOK_DATA_CHARS handler calls in doCdataSection
Updated packages:
  • expat-2.5.0-1.el9_2.tuxcare.els14.i686.rpm
    sha:099332f598851bb87c16b26c306a5b52da3589685e206d06db4a9f935d3215f3
  • expat-2.5.0-1.el9_2.tuxcare.els14.x86_64.rpm
    sha:fda320efec833d1f3c8f470a3671732b1753fa0f15c3db71bd1d5a9b4da4433b
  • expat-devel-2.5.0-1.el9_2.tuxcare.els14.i686.rpm
    sha:75dc7409dd6a8290f476fca0d7117df32660384e0fb258f84482a0865faf726b
  • expat-devel-2.5.0-1.el9_2.tuxcare.els14.x86_64.rpm
    sha:afc55fb1850e1f30e51a19359ac06fe517786d65d881d0b43c560fea5f88b5a0
  • expat-static-2.5.0-1.el9_2.tuxcare.els14.x86_64.rpm
    sha:4fc38bb9047fd0756ef2a51e123e1e87f43f0a94c7def42f8a6bb53b4e94dfa0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.