[CLSA-2026:1787086661] expat: Fix of CVE-2026-56407
Type:
security
Severity:
Important
Release date:
2026-08-18 20:57:51 UTC
Description:
- CVE-2026-56407: prevent signed integer overflow of the entity textLen field by capping the entityValuePool length at INT_MAX in doProlog
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els4.i686.rpm
    sha:644d7743a537771e0b7f8e7fabaf78e9cca95b2d25d84c787a729eb4f7004f82
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els4.x86_64.rpm
    sha:03453635bf561676d1b031a32ee16ff4c64542516e85658a7eb21301426528a8
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els4.i686.rpm
    sha:69cf0633aa540f0c78bf9e488d98bda2664f737fb2ee64d33b6f4b1696e5b3ab
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els4.x86_64.rpm
    sha:53fef3d47a61517b08bd63237d9d959e85a128463acd3cfbeae58e4483440718
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els4.i686.rpm
    sha:a3bf0c5fbf12042a4e364f0a717c7e1afab5408951d0bf56a6ce63b396d9faa1
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els4.x86_64.rpm
    sha:8a19dc7c75cce4ae1f69a222d224cbbc6aa9e772e01d2285afb6fb708aa4705b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.