libexpat 2.9.0 fixes two vulnerabilities
libexpat 2.9.0 patches CVE-2026-77214 and CVE-2026-102633, including a 32-bit integer overflow.
Sebastian Pipping told oss-security that libexpat 2.9.0, also called Expat 2.9.0, fixes two vulnerabilities. CVE-2026-102633 is an integer overflow in expat_realloc on 32-bit platforms. CVE-2026-77214 adds validation of the len parameter against available buffer capacity in XML_ParseBuffer. The note does not say either flaw is being exploited.
- Expat 2.9.0 fixes CVE-2026-77214 and CVE-2026-102633.
- CVE-2026-102633 is an integer overflow in expat_realloc on 32-bit platforms.
- CVE-2026-77214 validates XML_ParseBuffer length against buffer capacity.
- The announcement does not report exploitation in the wild.
Vulnerabilities mentionedAll →
- CVE-2026-1026338.2—Integer Overflow in libexpat expat_realloc() on 32-Bit Platforms (v2.7.2–2.8.5)published · libexpat project libexpat (expat XML parser library)
- CVE-2026-772148.3—Heap buffer over-read in libexpat XML_ParseBufferpublished · libexpat project libexpat
| CVE | Vulnerability | CVSS | EPSS | Flags |
|---|
Posted by Sebastian Pipping on Oct 05 Hello oss-security, just a quick note that libexpat 2.9.0 (or "Expat 2.9.0") released today is fixing two vulnerabilities: - CVE-2026-77214 - CVE-2026-102633 The related part of the change log is this: #1392 CVE-2026-102633 -- Integer overflow in function expat_realloc on 32bit platforms #1393 CVE-2026-77214 -- Validate parameter `len` against available buffer capacity in XML_ParseBuffer Some key...
This source does not provide full text. Read it at seclists.org.