expat-2.5.0-6.el9_8.5
エラータID: AXSA:2026-1939:13
Expat is a C library for parsing XML documents.
Security Fix(es):
* expat: Expat: Denial of Service via quadratic complexity in attribute processing (CVE-2026-66046)
* expat: Expat: XML Injection via Malformed UTF-16 Input (CVE-2026-93990)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-66046
Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.
CVE-2026-93990
Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds.
Update packages.
Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.
Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds.
N/A
SRPMS
- expat-2.5.0-6.el9_8.5.src.rpm
MD5: a8885930dbcb3fd5bc70ec30e1a98683
SHA-256: 1b571b2fb0fe059390f313a4317771bb0bbbab56bc695c37ae06a435860c7813
Size: 8.02 MB
Asianux Server 9 for x86_64
- expat-2.5.0-6.el9_8.5.i686.rpm
MD5: dae7cc515f58c2d06f319bb52496390b
SHA-256: bd16c2aca46ec6f9c41db04441906cc805ffcca3b657c7ce6a0281649a074730
Size: 122.09 kB - expat-2.5.0-6.el9_8.5.x86_64.rpm
MD5: cc22e066940b00cbf4aefe9ef8611883
SHA-256: 0193d42c59248956c67a5526f69638e5137ef06f9c240cf699635beeee6dd889
Size: 119.50 kB - expat-devel-2.5.0-6.el9_8.5.i686.rpm
MD5: 393b4bc72f82f45f4abadc34e662c76a
SHA-256: 89169aec62f9f6c46d7834d96ec0539f2e09ba60814e066a8dc6b633dc0dc52f
Size: 56.27 kB - expat-devel-2.5.0-6.el9_8.5.x86_64.rpm
MD5: f8bb3cbb0c0aaf5538a859743f37cb37
SHA-256: d70a44d2f01327a765166f09dbe87aa3b23a7cb17fe2f11c41776db1b439e228
Size: 56.27 kB