-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4765-1 [email protected]
https://www.debian.org/lts/security/ Andrej Shadura
August 31, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : expat
Version : 2.5.0-1+deb12u3
CVE ID : CVE-2026-50219 CVE-2026-56131 CVE-2026-56403
CVE-2026-56404 CVE-2026-56405 CVE-2026-56406
CVE-2026-56407 CVE-2026-56408 CVE-2026-56409
CVE-2026-56410 CVE-2026-56411 CVE-2026-56412
CVE-2026-72522 CVE-2026-76957
CVE-2026-50219, CVE-2026-56131, CVE-2026-76957
Calling certain libexpat functions from within a handler could cause
use-after-free.
CVE-2026-56403, CVE-2026-56404, CVE-2026-56405, CVE-2026-56406,
CVE-2026-56407, CVE-2026-56408, CVE-2026-56409, CVE-2026-56410,
CVE-2026-56411
Integer overflow in several functions.
CVE-2026-56412
A missing reentrancy guard around CDATA section handler calls could
cause use-after-free.
CVE-2026-72522
An out-of-bounds read in expat's internal UTF-16 conversion functions
could cause an infinite loop when processing crafted input, resulting
in a denial of service.
For Debian 12 bookworm, these problems have been fixed in version
2.5.0-1+deb12u3.
We recommend that you upgrade your expat packages.
For the detailed security status of expat please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/expat
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iHUEARYKAB0WIQSD3NF/RLIsyDZW7aHoRGtKyMdyYQUCapXv/QAKCRDoRGtKyMdy
YTuTAQCTyJt1MZ51MU6bvfOr0CgaWeec77mAZUH3t/aDaqYulAD/TUyId7UxJIA+
NCZveJV6cCm12mVTxQSI0xVahCYuzww=
=4nsT
-----END PGP SIGNATURE-----