[CLSA-2026:1790239193] expat: Fix of CVE-2026-66046
Type:
security
Severity:
Important
Release date:
2026-09-24 08:40:04 UTC
Description:
- CVE-2026-66046: fix quadratic runtime in attribute value normalization by resolving an attribute's declared type through the default-attribute hash table instead of an O(n^2) scan of the element's default attributes
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els8.i686.rpm
    sha:203ef32ecc3ff1a22f52cb8dfaf166fa299d6483228f5b155737fdde040a1b5c
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els8.x86_64.rpm
    sha:1a453f5e110f1721b85c834781139f8b99dbc93670a3df94904f34af13fffb85
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els8.i686.rpm
    sha:c377542c6a5eca4e23ab6b30989b696423a02a6ce9da308613492f4d0cbb9d9f
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els8.x86_64.rpm
    sha:fa0af982fee12481ff09680514e4f0c43e79ed04b4facb5f067a719f06326b61
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els8.i686.rpm
    sha:432c04d88ce80d534aedb842074b76c520c7168a802d9e2dfdc681a0b11f14ba
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els8.x86_64.rpm
    sha:00180fcc7aa3062db11ff6c8d26347893f4283229391979efd74909d59278f56
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.