Yes, once they expire they can sit there. You may need to remove them using a Powershell script like this one to clear them out. If they have similar names to existing ones then you
From the troubleshooting guide:
Reduce the number of certificate values on the on-premises AD object (15 or less) by removing values that are no longer in use by your organization. This is suitable if the attribute bloat is caused by expired or unused certificates. You can use the PowerShell script available here to help find, backup, and delete expired certificates in your on-premises AD. Before deleting the certificates, it is recommended that you verify with the Public-Key-Infrastructure administrators in your organization.
See also: https://learn.microsoft.com/en-us/azure/active-directory/hybrid/reference-connect-adsynctools