[ALSA-2026:74001] Important: expat security update
Type:
security
Severity:
important
Release date:
2026-10-01
Description:
Expat is a C library for parsing XML documents. Security Fix(es): * expat: Expat: Denial of Service via quadratic complexity in attribute processing (CVE-2026-66046) * expat: Expat: XML Injection via Malformed UTF-16 Input (CVE-2026-93990) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 expat-devel-2.7.3-1.el10_2.5.aarch64.rpm 5447040fb05a0dc0bf3bb1ad3c660c6336bd4e2e23541651d7c2af4b00c28fae
aarch64 expat-2.7.3-1.el10_2.5.aarch64.rpm c2419008163b0cf73a990a166d8e3d0e4a9e1821b748fdb34fc94d8cd31cfd6c
ppc64le expat-devel-2.7.3-1.el10_2.5.ppc64le.rpm b3c0ff526cf0098eb2fc3631bef504b3173d83e556de77ce33c074b8c7358872
ppc64le expat-2.7.3-1.el10_2.5.ppc64le.rpm d2faf48fa74a3fb740c3d8e004e2b9c33b287ec0f39217dd3e15ebe9931cf63c
s390x expat-devel-2.7.3-1.el10_2.5.s390x.rpm 2cc341d23f8a1bd184352d268a97cdb55dfa820adeaa2c1756e318f1eb5658f4
s390x expat-2.7.3-1.el10_2.5.s390x.rpm f9d7b6f40d3cb7fd446db6bdf9e336087729346ad78c3123c5c522d65d614d8c
x86_64 expat-2.7.3-1.el10_2.5.x86_64.rpm 48e779989aba0b3c4ea8929a315a32cf0c82a6fa3290cf17f294e5d27015d886
x86_64 expat-devel-2.7.3-1.el10_2.5.x86_64.rpm 6e4f7bd028c902425cb58bf2b365cf98d79da24078e92815d32c027d8df6103f
x86_64_v2 expat-devel-2.7.3-1.el10_2.5.x86_64_v2.rpm 5d1310b36374412e9615fa9c50c57542359092b003be2d22921c4bc4bafac85c
x86_64_v2 expat-2.7.3-1.el10_2.5.x86_64_v2.rpm dfbc954c9f30c5daab73fd6b44a6db8b8bfe693f261d0e1607b17bac351b9741
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.