[CLSA-2026:1790919725] expat: Fix of CVE-2026-93990
Type:
security
Severity:
Important
Release date:
2026-10-02 05:42:16 UTC
Description:
- CVE-2026-93990: reject a UTF-16 high surrogate that is not followed by a low surrogate, so malformed UTF-16 can no longer hide the following code unit from the tokenizer
CVEs fixed:
Updated packages:
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els9.i686.rpm
    sha:3720164b6914aa440ea850ebb72ec4f1245b082495316c4bd37fd85018427a9d
  • expat-2.1.0-15.0.7.el7_9.tuxcare.els9.x86_64.rpm
    sha:dcead136c5f1a62534d6cd1f33475a73097098603077a4943a36aefd7ba7c44f
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els9.i686.rpm
    sha:3fdaa7304fcf035089d98ee9e78fd8295102c1f4e7b91467643990d1947ad56d
  • expat-devel-2.1.0-15.0.7.el7_9.tuxcare.els9.x86_64.rpm
    sha:211c9ee242847fa0178848e6ba7e61edb6fedbed7b85bedae03416616746d792
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els9.i686.rpm
    sha:de4b905de8208142572c42b3712be65395988f6eb625b550412ad93c0e8d313d
  • expat-static-2.1.0-15.0.7.el7_9.tuxcare.els9.x86_64.rpm
    sha:c97bd895c94f6153a226be29a715114d7618992fd5a3d9b258684080741e2759
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.