Home / mailingsPDF  

[USN-8790-1] Expat vulnerabilities

Posted on 21 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8790-1
September 21, 2026

expat vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in Expat.

Software Description:
- expat: XML parsing C library

Details:

It was discovered that Expat could be made to allocate large amounts of
memory when parsing a small crafted document. An attacker could possibly
use this issue to cause Expat to consume resources, leading to a denial of
service. This issue was only addressed in Ubuntu 24.04 LTS.
(CVE-2025-59375)

It was discovered that Expat incorrectly handled empty external parameter
entity content. An attacker could possibly use this issue to cause Expat to
crash, resulting in a denial of service. (CVE-2026-32776)

It was discovered that Expat incorrectly handled certain DTD content. An
attacker could possibly use this issue to cause Expat to enter an infinite
loop, resulting in a denial of service. (CVE-2026-32777)

It was discovered that Expat incorrectly handled memory when retrying after
an earlier out-of-memory condition. An attacker could possibly use this
issue to cause Expat to crash, resulting in a denial of service.
(CVE-2026-32778)

It was discovered that Expat performed attribute name collision checks
inefficiently. An attacker could possibly use this issue to cause Expat to
consume resources when processing a moderately sized crafted XML document,
resulting in a denial of service. This issue was only addressed in Ubuntu
24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-45186)

It was discovered that Expat used insufficient entropy, allowing hash
flooding through a crafted XML document. An attacker could possibly use
this issue to cause Expat to consume resources, leading to a denial of
service. This issue was only addressed in Ubuntu 14.04 LTS, Ubuntu 24.04
LTS, and Ubuntu 26.04 LTS. (CVE-2026-41080)

It was discovered that Expat did not track handler call depth for certain
functions called from within handlers, leading to a use-after-free. An
attacker could possibly use this issue to cause Expat to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2026-50219, CVE-2026-56412)

It was discovered that Expat incorrectly handled certain values, leading to
integer overflows. An attacker could possibly use this issue to cause Expat
to crash, resulting in a denial of service. (CVE-2026-56403,
CVE-2026-56404, CVE-2026-56405)

It was discovered that Expat incorrectly handled certain values, leading to
an integer overflow. An attacker could possibly use this issue to cause
Expat to crash, resulting in a denial of service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and
Ubuntu 26.04 LTS. (CVE-2026-56408)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
expat 2.7.4-1ubuntu0.1
libexpat1 2.7.4-1ubuntu0.1
libexpat1-dev 2.7.4-1ubuntu0.1

Ubuntu 24.04 LTS
expat 2.6.1-2ubuntu0.5
libexpat1 2.6.1-2ubuntu0.5
libexpat1-dev 2.6.1-2ubuntu0.5

Ubuntu 22.04 LTS
expat 2.4.7-1ubuntu0.8
libexpat1 2.4.7-1ubuntu0.8
libexpat1-dev 2.4.7-1ubuntu0.8

Ubuntu 20.04 LTS
expat 2.2.9-1ubuntu0.8+esm2
Available with Ubuntu Pro
libexpat1 2.2.9-1ubuntu0.8+esm2
Available with Ubuntu Pro
libexpat1-dev 2.2.9-1ubuntu0.8+esm2
Available with Ubuntu Pro

Ubuntu 18.04 LTS
expat 2.2.5-3ubuntu0.9+esm4
Available with Ubuntu Pro
libexpat1 2.2.5-3ubuntu0.9+esm4
Available with Ubuntu Pro
libexpat1-dev 2.2.5-3ubuntu0.9+esm4
Available with Ubuntu Pro

Ubuntu 16.04 LTS
expat 2.1.0-7ubuntu0.16.04.5+esm13
Available with Ubuntu Pro
lib64expat1 2.1.0-7ubuntu0.16.04.5+esm13
Available with Ubuntu Pro
lib64expat1-dev 2.1.0-7ubuntu0.16.04.5+esm13
Available with Ubuntu Pro
libexpat1 2.1.0-7ubuntu0.16.04.5+esm13
Available with Ubuntu Pro
libexpat1-dev 2.1.0-7ubuntu0.16.04.5+esm13
Available with Ubuntu Pro

Ubuntu 14.04 LTS
expat 2.1.0-4ubuntu1.4+esm12
Available with Ubuntu Pro
lib64expat1 2.1.0-4ubuntu1.4+esm12
Available with Ubuntu Pro
lib64expat1-dev 2.1.0-4ubuntu1.4+esm12
Available with Ubuntu Pro
libexpat1 2.1.0-4ubuntu1.4+esm12
Available with Ubuntu Pro
libexpat1-dev 2.1.0-4ubuntu1.4+esm12
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8790-1
CVE-2025-59375, CVE-2026-32776, CVE-2026-32777, CVE-2026-32778,
CVE-2026-41080, CVE-2026-45186, CVE-2026-50219, CVE-2026-56403,
CVE-2026-56404, CVE-2026-56405, CVE-2026-56408, CVE-2026-56412

Package Information:
https://launchpad.net/ubuntu/+source/expat/2.7.4-1ubuntu0.1
https://launchpad.net/ubuntu/+source/expat/2.6.1-2ubuntu0.5
https://launchpad.net/ubuntu/+source/expat/2.4.7-1ubuntu0.8

--===============5294799473126394532==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP