[CLSA-2026:1790238755] expat: Fix of CVE-2026-66046
Type:
security
Severity:
Important
Release date:
2026-09-24 10:56:03 UTC
Description:
- CVE-2026-66046: fix quadratic runtime in attribute value normalization by resolving an attribute's declared type through the default-attribute hash table instead of an O(n^2) scan of the element's default attributes
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els8.i686.rpm
    sha:ad56777c3ff65204095b82ac8f24df72ef5085fb8b11daa4f5ce8adbd422b3ed
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els8.x86_64.rpm
    sha:2bd42c62c70e16d2e9f0a96f1041b1425c1abfb1a4a89315b4046792afac23b0
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els8.i686.rpm
    sha:2c972772ed79ad820fdfb3399ee2f9af13dc0182e5b88437f07875f939e02e57
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els8.x86_64.rpm
    sha:f85cf9619a8a4fbe651294c0ec0cdac1759781496606353485433c901c959d92
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els8.i686.rpm
    sha:a821be1e2902c36e2c8888314f15cfc8155e32bff3b8e78fe2337790de2ad955
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els8.x86_64.rpm
    sha:99ce4f3e38937a25e13f702ca633e02129ace2d8360392b6ec55121750a27d19
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.