[ALSA-2026:72448] Important: expat security update
Type:
security
Severity:
important
Release date:
2026-09-28
Description:
Expat is a C library for parsing XML documents. Security Fix(es): * expat: Expat: Denial of Service via quadratic complexity in attribute processing (CVE-2026-66046) * expat: Expat: XML Injection via Malformed UTF-16 Input (CVE-2026-93990) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 expat-devel-2.5.0-4.el8_10.aarch64.rpm 167ee0d0540cc40ee9394286a0a0199d9e42ab6487607e53a4b4fb8b2a86a747
aarch64 expat-2.5.0-4.el8_10.aarch64.rpm da749294b4f203a7d62f1949cc5688c8248df1ee13aa5c8f5d7c6c71421b7e20
i686 expat-2.5.0-4.el8_10.i686.rpm 658e83607e60141411fd8c9de2f6739bba97afbf0c9103a37de59adb99643c5d
i686 expat-devel-2.5.0-4.el8_10.i686.rpm b850d59a5393717e635a286933639cfe3c325801e72aadbb88b8df0c54488592
ppc64le expat-devel-2.5.0-4.el8_10.ppc64le.rpm 3c879f4e392f8b4ba420c699b2de859cbd8f170fe7659b0b80795f675d6663b7
ppc64le expat-2.5.0-4.el8_10.ppc64le.rpm c9ccd00ef402455383b97aabadaa5074bbab3a6e2017b07ba4a0b41752890a38
s390x expat-devel-2.5.0-4.el8_10.s390x.rpm 4be9e6b88c9fe55995bad38cd724736f1fdd311ccaf8c6717f6965506a6fe2b1
s390x expat-2.5.0-4.el8_10.s390x.rpm bcdff63ade824e307374add8de48d6fe75a0f8a754258aabc0c11f26c4dc09f8
x86_64 expat-devel-2.5.0-4.el8_10.x86_64.rpm 1df3f003f7885b23ab6aa92b907b1158799c5cae64fe40c31f2843bb669d3d74
x86_64 expat-2.5.0-4.el8_10.x86_64.rpm fd34d23c37db699d2307f8b251749090bb0495e4d888210b448e52f0e3a1a3f7
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.