[CLSA-2026:1790239270] expat: Fix of CVE-2026-66046
Type:
security
Severity:
Important
Release date:
2026-09-24 08:41:22 UTC
Description:
- CVE-2026-66046: fix quadratic runtime in attribute value normalization by resolving an attribute's declared type through the default-attribute hash table instead of an O(n^2) scan of the element's default attributes
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els8.i686.rpm
    sha:8ed1492f9590420a9393df4bfd17b0295eee90249c2559797c7ff178d0b220bb
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els8.x86_64.rpm
    sha:f2e55941f15e9df9618a09f4653fbb999348822fb73bfdca6802e9a32d3a35ee
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els8.i686.rpm
    sha:b147a17f67c30cb9991b2797f1589cf3c4c2b519c6f43791b4d7fc0c01f076b8
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els8.x86_64.rpm
    sha:b7316b796ba895f329dc7f1f2c031ba3a6577ff57de68631c3afa7dcc1680c11
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els8.i686.rpm
    sha:fa82e295c755e0ef48f28bb80c2ba6a26fabe4173761d8602855b334ffa3480a
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els8.x86_64.rpm
    sha:b8b508cf4524bca747bb2d68661ed389c76e3baf39b7382038ff986b02ef11a4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.