[DSA 6404-1] expat security update
Aron Xu <[email protected]> Thu, 30 Jul 2026 08:38:59 +0000
| Newsgroups | gmane.linux.debian.user.security.announce |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6404-1 [email protected] https://www.debian.org/security/ Aron Xu July 30, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : expat CVE ID : CVE-2025-59375 CVE-2026-24515 CVE-2026-25210 CVE-2026-32776 CVE-2026-32777 CVE-2026-32778 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 Multiple security issues were discovered in expat, an XML parsing C library, including integer overflows, out-of-bounds write, NULL pointer dereferences, excessive resource consumption, and memory corruption through re-entrant parser API calls, which may result in denial of service or potentially the execution of arbitrary code. For the stable distribution (trixie), this problem has been fixed in version 2.8.2-1~deb13u1. We recommend that you upgrade your expat packages. For the detailed security status of expat please refer to its security tracker page at: https://security-tracker.debian.org/tracker/expat Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: [email protected] -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEExq6D0hxncEPaPayX+GQ1dHE8m64FAmprDScACgkQ+GQ1dHE8 m66/1AgA2TXLI6l3FjGr0rgpqLizVRl1NjB3SFMtZ3pDYFgQ24kYJ92goKq7Gwd/ ELKq1Lx0ifIe1/JgiavE5COxYTxnTu7r4GRseT+zQeboidtMx4+DMRzQ0SLXl0AR Lzz3NH5EAAPbFJd8PgEqTqZVumGpPocscHxQW3QwL9g9D+AWBUkGGHnFCVH5MjdG pPFOPZ7+daAsCX+g5MMNagpNAoW/2/bchcFssJYxzYsIWfTVoH3jVGUkzHo4mqur JOlCM2FzkZVRoxA+bo+qmmZp71aSJA5RJt16F8PJMtGUY30Z1ahpbAzTVPWQ+hoP P6m17T8XnlevqmVdu2A+cgf0RmOcLQ== =wP7J -----END PGP SIGNATURE-----