[CLSA-2026:1787062730] expat: Fix of CVE-2026-56407
Type:
security
Severity:
Important
Release date:
2026-08-18 14:19:01 UTC
Description:
- CVE-2026-56407: prevent signed integer overflow of the entity textLen field by capping the entityValuePool length at INT_MAX in doProlog
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els4.i686.rpm
    sha:d6884c68fd43a38c160dd36455f68312011db2c40a31bd554a66b9c6e16e6d31
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els4.x86_64.rpm
    sha:40acfc340a5ad6ad3502d7b637fa66b44a655ed9bde4fe22c9b9d267d6b9c55e
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els4.i686.rpm
    sha:3151c864da0747ab48bf71b3e968512c506f9f75aeafcfed13d5084af501873e
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els4.x86_64.rpm
    sha:1048d2a3a3c6a869fdacf736859173251cd9d6eb9e3e486c69462e05d040575c
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els4.i686.rpm
    sha:9f1f12dd5081ddd0634e5af7e535238c2349f7d0cc9d80209c6c25ba5997e2b8
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els4.x86_64.rpm
    sha:9d97a3facb8fdffb5a9ea138e081bbc21595a42d2a78384624d5aa5caa6239f3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.