SECURITY UPDATE: Denial of service via quadratic attribute-name
collision check in libexpat before 2.8.1
debian/patches/CVE-2026-45186.patch: introduce per-element
defaultAttsNames hash table and use it for O(1) attribute
collision detection in defineAttribute