CVE-2026-72522 is an out-of-bounds read and infinite loop vulnerability in
Expat's *_toUtf16 functions caused by mis-classifying low surrogates as
high surrogates.

Our Yocto configuration is not affected by this vulnerability:
- Expat is compiled with EXPAT_CHAR_TYPE=char (8-bit character representation).
- Neither XML_UNICODE nor XML_UNICODE_WCHAR_T is defined.
- The vulnerable *_toUtf16 functions are only invoked when Expat's internal
  character type is 16-bit (ushort or wchar_t).
- In 8-bit mode, Expat handles conversion using *_toUtf8 functions even when
  parsing UTF-16 encoded XML inputs, rendering the vulnerable code path
  unreachable.

Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-72522
[2] 
https://github.com/libexpat/libexpat/pull/1296/changes/8fbfb52fa88e040e8b0b7a9d39f260d6a9e8b6db

Signed-off-by: Jaipaul Cheernam <[email protected]>
---
 meta/recipes-core/expat/expat_2.7.5.bb | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/meta/recipes-core/expat/expat_2.7.5.bb 
b/meta/recipes-core/expat/expat_2.7.5.bb
index 890ee5b7d3..da35b8f9ff 100644
--- a/meta/recipes-core/expat/expat_2.7.5.bb
+++ b/meta/recipes-core/expat/expat_2.7.5.bb
@@ -57,3 +57,6 @@ do_install_ptest:class-target() {
 BBCLASSEXTEND += "native nativesdk"
 
 CVE_PRODUCT = "expat libexpat"
+
+CVE_STATUS[CVE-2026-72522] = "not-applicable-config: Needs Expat compiled with 
16bit character support , Issue only affects firefox/Windows. \
+EXPAT_CHAR_TYPE:STRING=char is for Yocto builds"
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#243625): 
https://lists.openembedded.org/g/openembedded-core/message/243625
Mute This Topic: https://lists.openembedded.org/mt/120791940/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to