Amazon Linux 2027 Preview Security Advisory: ALAS2027-2026-081
Advisory Release Date: 2026-09-28 09:00 Pacific
Advisory Updated Date: 2026-09-28 09:00 Pacific
FAQs regarding Amazon Linux ALAS/CVE Severity
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur, (CVE-2026-50219)
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation). (CVE-2026-56131)
libexpat before 2.8.2 has an integer overflow in storeAtts. (CVE-2026-56403)
libexpat before 2.8.2 has an integer overflow in addBinding. (CVE-2026-56404)
libexpat before 2.8.2 has an integer overflow in getAttributeId. (CVE-2026-56405)
libexpat before 2.8.2 has an integer overflow in copyString. (CVE-2026-56408)
xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. (CVE-2026-56409)
xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. (CVE-2026-56410)
xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations. (CVE-2026-56411)
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219. (CVE-2026-56412)
Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options. (CVE-2026-66046)
Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to read the attIndex member past allocated memory boundaries, resulting in failure to normalize whitespace in non-CDATA attributes or a wild pointer dereference causing a segfault. This vulnerability was introduced by the fix for CVE-2026-66046. (CVE-2026-76641)
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412. (CVE-2026-76957)
Affected Packages:
expat
Issue Correction:
Run yum update expat to update your system.
aarch64:
expat-static-2.8.3-1.amzn2027.aarch64
expat-debuginfo-2.8.3-1.amzn2027.aarch64
expat-devel-2.8.3-1.amzn2027.aarch64
expat-2.8.3-1.amzn2027.aarch64
expat-debugsource-2.8.3-1.amzn2027.aarch64
src:
expat-2.8.3-1.amzn2027.src
x86_64:
expat-devel-2.8.3-1.amzn2027.x86_64
expat-static-2.8.3-1.amzn2027.x86_64
expat-2.8.3-1.amzn2027.x86_64
expat-debuginfo-2.8.3-1.amzn2027.x86_64
expat-debugsource-2.8.3-1.amzn2027.x86_64