[CLSA-2026:1790919304] expat: Fix of CVE-2026-93990
Type:
security
Severity:
Important
Release date:
2026-10-02 05:35:15 UTC
Description:
- CVE-2026-93990: reject a UTF-16 high surrogate that is not followed by a low surrogate, so malformed UTF-16 can no longer hide the following code unit from the tokenizer
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.amzn2.tuxcare.els9.aarch64.rpm
    sha:9c424d0a84c0c64f6cd937d1da918a693995613b800c6413e0b804510daf4c34
  • expat-2.1.0-15.0.7.amzn2.tuxcare.els9.i686.rpm
    sha:3fa99ae925c4faa96aa2c41896a12a410c9664038853598eedeafab7e91afb12
  • expat-2.1.0-15.0.7.amzn2.tuxcare.els9.x86_64.rpm
    sha:56f70c24eb12ee11a00be6a43d163bba45a4c89404a52f419a9fce31f3f98033
  • expat-devel-2.1.0-15.0.7.amzn2.tuxcare.els9.aarch64.rpm
    sha:2d4f5f44af682fdaf4edbf8ebf0c6bdcde9a8bdd043be1bad45a3b4cc8c940d4
  • expat-devel-2.1.0-15.0.7.amzn2.tuxcare.els9.i686.rpm
    sha:2bc51a0f0a04fe0df70755509d1c821d3199b92fa34a5197e4324fbb4caa8e90
  • expat-devel-2.1.0-15.0.7.amzn2.tuxcare.els9.x86_64.rpm
    sha:029f6373a967a0be2b614705d01566664be062516608e8747e3367f0acb4944d
  • expat-static-2.1.0-15.0.7.amzn2.tuxcare.els9.aarch64.rpm
    sha:0b19ddb5f0c46dfd2d17477fc7a124889ddbe993cdc35fbde604134dfbc4a5b3
  • expat-static-2.1.0-15.0.7.amzn2.tuxcare.els9.i686.rpm
    sha:522a328d4e98c1f84509677dbda20201d23796fd54214b7e4d04df7aee4c4546
  • expat-static-2.1.0-15.0.7.amzn2.tuxcare.els9.x86_64.rpm
    sha:57ea1caafc9bcb07e6a467c140db19631b1c8ac588477182ccddb9ab7587787b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.