RHSA-2026:54869MediumCVSS 6.2

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

Published
August 14, 2026
Last Modified
August 23, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-72522 — expat: libexpat: Denial of Service due to incorrect Unicode surrogate handling

🎯 Affected products4

  • Red Hat Hardened Images
  • expat-main@aarch64 as a component of Red Hat Hardened Images
  • expat-main@src as a component of Red Hat Hardened Images
  • expat-main@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Limit exposure by restricting the parsing of untrusted or unverified XML inputs, and validate incoming XML documents for malformed character sequences before processing. Additionally, enforce process-level CPU resource limits and parsing timeouts to prevent system-wide Denial of Service from infinite parsing loops.

🔗 References (5)