[El-errata] ELSA-2026-74001 Important: Oracle Linux 10 expat security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Mon Oct 5 18:15:50 UTC 2026


Oracle Linux Security Advisory ELSA-2026-74001

http://linux.oracle.com/errata/ELSA-2026-74001.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
expat-2.7.3-1.el10_2.5.x86_64.rpm
expat-devel-2.7.3-1.el10_2.5.x86_64.rpm

aarch64:
expat-2.7.3-1.el10_2.5.aarch64.rpm
expat-devel-2.7.3-1.el10_2.5.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/expat-2.7.3-1.el10_2.5.src.rpm

Related CVEs:

CVE-2026-66046
CVE-2026-93990




Description of changes:

[2.7.3-61]
- CVE-2026-66046 expat: Expat: Denial of Service via quadratic complexity
  in attribute processing

[2.7.3-60]
- CVE-2026-93990 expat: Expat: XML Injection via Malformed UTF-16 Input

[2.7.3-59]
- Fix CVE-2026-56132: out-of-bound scaffolding index store in doProlog

[2.7.3-58]
- Fix CVE-2026-50219: forbid XML_ParserFree/Reset from handlers

[2.7.3-57]
- expat: backport CVE-2026-45186 fix (attribute collision check DoS)

[2.7.3-56]
- Rebase to 2.7.3 and add VCS tag

* Thu Jun 05 2025 psklenar at redhat.com <psklenar at redhat.com>
- https://issues.redhat.com/browse/RHELMISC-13073

* Fri Mar 28 2025 Tomas Korbar <tkorbar at redhat.com>
- Fix behavior change caused by fix for CVE-2024-8176

* Fri Mar 14 2025 Tomas Korbar <tkorbar at redhat.com>
- Fix CVE-2024-8176

* Thu Nov 07 2024 Tomas Korbar <tkorbar at redhat.com>
- Rebase to 2.6.4




More information about the El-errata mailing list