USN-8872-1: libxmltok vulnerabilities
Ubuntu fixed libxmltok integer flaws CVE-2026-56404 and CVE-2026-56405 that can crash processes via crafted files.
Ubuntu Security Notice USN-8872-1 says Expat, bundled in the xmltok library, mishandles certain integer arithmetic. If a user or automated system opens a specially crafted file, an attacker could cause a denial of service. The issues are tracked as CVE-2026-56404 and CVE-2026-56405. The notice does not describe exploitation in the wild.
- USN-8872-1 covers integer-arithmetic flaws in Expat inside libxmltok.
- CVE-2026-56404 and CVE-2026-56405 can cause denial of service.
- A crafted file must be opened by a user or automated system.
- Ubuntu does not report active exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-564046.9<1%libexpat before 2.8.2 has an integer overflow in addBindingpublished · libexpat project libexpat+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-56404+1 related CVE | libexpat before 2.8.2 has an integer overflow in addBinding |
It was discovered that Expat, contained with the xmltok library did not correctly handle certain integer arithmetic. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly cause a denial of service. (CVE-2026-56404, CVE-2026-56405)
This source does not provide full text. Read it at ubuntu.com.