[CLSA-2026:1790917795] expat: Fix of CVE-2026-93990
Type:
security
Severity:
Important
Release date:
2026-10-02 17:06:16 UTC
Description:
- CVE-2026-93990: reject a UTF-16 high surrogate that is not followed by a low surrogate, so malformed UTF-16 can no longer hide the following code unit from the tokenizer
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els9.i686.rpm
    sha:bc2b4d4fb64ca997d9caa5314391ba872f88dbe5a7ad00fe6e219ff60a5699e3
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els9.x86_64.rpm
    sha:e7738ccb8011018869bde200000819823688b76d8e424ba2317ede39613f2c52
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els9.i686.rpm
    sha:9d2e68bdf58522c496fe442049047ce020a6ba7f1b45ea23c8dbcb8d508a25fc
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els9.x86_64.rpm
    sha:f007aec9d83aa3c8cf60af956c829ca17f290e683dc7040523c02800dfd09a2b
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els9.i686.rpm
    sha:da06c32ef6bfeb21cf5e1105db2850062585262ecfd5424f99a4ae1379a17e1e
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els9.x86_64.rpm
    sha:76af195d64d6cd7f8e6b5e37fdd0658bdae6b4a53c099c705c075414b44fd502
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.