USN-8813-1: Expat vulnerabilities
Ubuntu's USN-8813-1 patches Expat flaws that can crash the parser or allow code execution.
Ubuntu published USN-8813-1 for vulnerabilities in the Expat XML parser. Integer-arithmetic issues (CVE-2026-56406, CVE-2026-56407, CVE-2026-56409, CVE-2026-56410, CVE-2026-56411) could let an attacker cause a denial of service. Separate flaws in handler-call-depth tracking (CVE-2026-56131) and memory handling (CVE-2026-56132) could crash Expat or lead to arbitrary code execution. The notice also describes incorrect Unicode handling; it does not report active exploitation.
- USN-8813-1 covers multiple Expat flaws in Ubuntu packages.
- Integer-arithmetic bugs may allow denial of service.
- Handler-depth and memory bugs may crash Expat or allow code execution.
- No exploitation in the wild is reported in the notice.
Vulnerabilities mentionedAll →
- CVE-2026-561326.9<1%In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there…published · libexpat project libexpat+1 related
- CVE-2026-564066.9<1%
It was discovered that Expat did not correctly handle certain integer arithmetic. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-56406, CVE-2026-56407, CVE-2026-56409, CVE-2026-56410, CVE-2026-56411) It was discovered that Expat did not correctly track handler call depth. An attacker could possibly use this issue to cause Expat to crash or execute arbitrary code. (CVE-2026-56131) It was discovered that Expat did not correctly handle certain memory operations. An attacker could possibly use this issue to cause Expat to crash or execute arbitrary code. (CVE-2026-56132) It was discovered that Expat did not correctly handle certain Unicode characters. An…
This source does not provide full text. Read it at ubuntu.com.