Home / mailingsPDF  

[SECURITY] [DSA 6404-1] expat security update

Posted on 30 July 2026
Debian Security Advisory

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6404-1 security@debian.org
https://www.debian.org/security/ Aron Xu
July 30, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : expat
CVE ID : CVE-2025-59375 CVE-2026-24515 CVE-2026-25210 CVE-2026-32776
CVE-2026-32777 CVE-2026-32778 CVE-2026-41080 CVE-2026-45186
CVE-2026-50219 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403
CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407
CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411
CVE-2026-56412

Multiple security issues were discovered in expat, an XML parsing C library,
including integer overflows, out-of-bounds write, NULL pointer dereferences,
excessive resource consumption, and memory corruption through re-entrant
parser API calls, which may result in denial of service or potentially the
execution of arbitrary code.

For the stable distribution (trixie), this problem has been fixed in
version 2.8.2-1~deb13u1.

We recommend that you upgrade your expat packages.

For the detailed security status of expat please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/expat

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

 

TOP