Red Hat Patches Two Expat XML Parser Flaws Across Enterprise Linux 9 Platforms
Red Hat published security advisory RHSA-2026:72663 on 28 September 2026, delivering an updated expat package for Red Hat Enterprise Linux 9 and rating the issue Important. Expat is the small C library that huge numbers of Linux applications quietly rely on to parse XML documents, which is what makes an advisory against it broader than its package size suggests. Two vulnerabilities are addressed: CVE-2026-66046, a denial of service caused by quadratic complexity in attribute processing, and CVE-2026-93990, an XML injection issue triggered by malformed UTF-16 input. The fixed build is expat-2.5.0-6.el9_8.5, shipped for x86_64, s390x, ppc64le and aarch64. Affected channels include RHEL 9 mainline, Extended Update Support 9.8, Update Services for SAP Solutions 9.8 for x86_64 and Power LE, the four-years-of-updates streams, and the Extended Life Cycle 9.8 streams, so customers on long-life or SAP-aligned subscriptions are in scope alongside standard RHEL 9 estates.
Red Hat has not published an exploitation chain, proof-of-concept code or attacker tradecraft in this errata, and the mechanism is described only at a high level, with detailed severity scoring left to the individual CVE pages. What the advisory does state is the nature of each defect. CVE-2026-66046 concerns quadratic complexity during attribute processing, the classic algorithmic pattern where a comparatively small crafted input forces parsing work to grow disproportionately and consumes CPU until the consuming service degrades or stops responding. CVE-2026-93990 concerns XML injection arising from malformed UTF-16 input, meaning the parser can be steered into treating attacker-influenced bytes as document structure rather than as data. Red Hat tracks the second issue under Bugzilla 2538967. Both defects are reached through the data an application hands to expat, so the practical exposure of any given host depends on whether a locally installed service accepts XML from untrusted sources rather than on any network port expat opens itself, since the library opens none.
The strategic concern with an expat advisory is reach rather than novelty. The library is linked by desktop components, configuration tooling, document handling utilities, middleware and application stacks, which means a single unpatched package can sit behind several unrelated services on the same host, and each of those services inherits the parsing weakness. On systems that accept XML from the internet, from partners or from uploaded files, a quadratic-complexity condition translates into an availability problem that needs no credentials and no privilege, while an injection condition that changes how a document is interpreted undermines the integrity of whatever decision the consuming application makes from that document. The presence of Extended Update Support, SAP Solutions and Extended Life Cycle streams in the affected list is notable, because those estates are typically the slowest moving and the most likely to carry the vulnerable build the longest. On current exploitation status, the evidence is limited and should be read plainly: FIRST EPSS puts CVE-2026-66046 at a 0.7 percent probability of exploitation in the next 30 days and CVE-2026-93990 at 0.4 percent, neither CVE appears in a confirmed in-the-wild exploitation report in the material reviewed, and the advisory itself describes no active campaign. That places this in the routine-but-real category: a fixed, vendor-acknowledged weakness in a component with unusually wide internal reach, where the risk grows with how long the older package survives in the estate rather than with any attacker activity observed today.
Attack Surface
Server OS, Endpoint OS, Supply Chain (Third-party vendors)
Tactics
Impact, Initial Access
Techniques
- T1499 – Endpoint Denial of Service
- T1499.004 – Application or System Exploitation
- T1190 – Exploit Public-Facing Application
SuperPRO's Threat Countermeasures Procedures
- Install expat-2.5.0-6.el9_8.5 or later on all Red Hat Enterprise Linux 9 hosts using dnf update expat, covering the expat, expat-devel, expat-debuginfo and expat-debugsource packages built from expat-2.5.0-6.el9_8.5.src.rpm.
- Prioritise the long-life channels named in RHSA-2026:72663 – Extended Update Support 9.8, Update Services for SAP Solutions 9.8 (x86_64 and ppc64le), the four-years-of-updates streams and Extended Life Cycle 9.8 – since these estates commonly lag mainline RHEL 9 patch cycles.
- Verify the installed build after patching with rpm -q –qf '%{NAME}-%{VERSION}-%{RELEASE}n' expat and confirm the release string reads 6.el9_8.5, then validate the downloaded RPM against the advisory SHA-256 values (for example e6e7edd632fdd1dc4ad94b19b7ab88646f3ef8c1c7956bac58985c3e7118a362 for expat-2.5.0-6.el9_8.5.x86_64.rpm).
- Restart or redeploy services that keep libexpat mapped in memory after the package upgrade, since a running process continues to use the old library – use needs-restarting -r or lsof | grep libexpat.so to identify affected daemons before scheduling the reboot.
- Use the Red Hat Lightspeed patch analysis feature referenced in the errata to enumerate which registered systems remain affected by RHSA-2026:72663, rather than relying on manual inventory across mixed 9.x and EUS 9.8 estates.
- Cap XML input on services that accept untrusted documents while patching is scheduled – enforce request body size limits and parser timeouts at the application or reverse-proxy layer, and alert on single-process CPU saturation during XML parsing, which is the observable signature of the quadratic attribute-processing condition in CVE-2026-66046.
- Inventory third-party and containerised workloads that bundle their own copy of expat 2.5.0 rather than linking the RHEL system library, as those images will not be remediated by the host dnf update and require a rebuild against the patched package.