[CLSA-2026:1790931787] expat: Fix of 6 CVEs
Type:
security
Severity:
Critical
Release date:
2026-10-02 09:03:35 UTC
Description:
- CVE-2026-25210: add an integer overflow check before the tag buffer doubling in doContent(), so the reallocation size can no longer wrap - CVE-2026-56407: cap the entity value pool length against signed integer overflow in doProlog() before it is stored into m_declEntity->textLen - CVE-2026-56408: add the upstream integer overflow guard to copyString(); with XML_Char == char as built here the guard is inert, and it takes effect only in an XML_UNICODE build where sizeof(XML_Char) > 1
Updated packages:
  • expat-2.5.0-6.el9_8.5.tuxcare.els1.aarch64.rpm
    sha:d9c5eb159e07df9d9bb43384a4205f81586a00e8de11324c48b62cfeae647a83
  • expat-2.5.0-6.el9_8.5.tuxcare.els1.i686.rpm
    sha:6c48fcea5d901c9f3643c81681cb8893890b58fd4aec8798e08596f7fb6e25ec
  • expat-2.5.0-6.el9_8.5.tuxcare.els1.x86_64.rpm
    sha:24bd4f4ca43b22db0d7e49c8cf0390b549fbbb38e75194ca1eeb02b8d409651c
  • expat-devel-2.5.0-6.el9_8.5.tuxcare.els1.aarch64.rpm
    sha:043a51058684ed7c8399646b5d2067b029457824ca77b8b05905e7b13fe025f7
  • expat-devel-2.5.0-6.el9_8.5.tuxcare.els1.i686.rpm
    sha:1a2c8fe9545c7de946ed119e8a4f3a6bdb8f39212644e91b37393172c0fbadca
  • expat-devel-2.5.0-6.el9_8.5.tuxcare.els1.x86_64.rpm
    sha:77bd449e0a1037f2f07600e13552ebf2495db31ff0d69055f86eb29702e6fa5a
  • expat-static-2.5.0-6.el9_8.5.tuxcare.els1.aarch64.rpm
    sha:2a374918a2dc19297f0a2253f756b29f69789c7a26cb4dacc043b3385f968522
  • expat-static-2.5.0-6.el9_8.5.tuxcare.els1.i686.rpm
    sha:8d3de8531dff22fa7e6b13d00edeeb771ef1dd89722af1f37f4544177c344ff0
  • expat-static-2.5.0-6.el9_8.5.tuxcare.els1.x86_64.rpm
    sha:3f3c2f98b41e8d51042506a9bf86794130f1effe0778cc5e378cbef1bbaf8277
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.