Home / mailings [USN-8813-1] Expat vulnerabilities
Posted on 24 September 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8813-1
September 24, 2026
expat vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Expat could be made to crash or run programs if it received specially
crafted input.
Software Description:
- expat: XML parsing C library
Details:
It was discovered that Expat did not correctly handle certain integer
arithmetic. An attacker could possibly use this issue to cause a denial of
service.
(CVE-2026-56406, CVE-2026-56407, CVE-2026-56409, CVE-2026-56410, CVE-2026-56411)
It was discovered that Expat did not correctly track handler call depth. An
attacker could possibly use this issue to cause Expat to crash or execute
arbitrary code. (CVE-2026-56131)
It was discovered that Expat did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause Expat to
crash or execute arbitrary code. (CVE-2026-56132)
It was discovered that Expat did not correctly handle certain Unicode
characters. An attacker could possibly use this issue to cause Expat to use
excessive resources, leading to a denial of service. (CVE-2026-72522)
It was discovered that Expat did not correctly process certain XML
attributes. A remote attacker could possibly use this issue to cause Expat
to use excessive resources, leading to a denial of service.
(CVE-2026-66046)
It was discovered that Expat did not correctly handle certain external
entities. An attacker could possibly use this issue to cause Expat to crash
or execute arbitrary code. (CVE-2026-76641)
It was discovered that Expat did not correctly track handler call depth
with custom encodings. An attacker could possibly use this issue to cause
Expat to crash or execute arbitrary code. (CVE-2026-76957)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
expat 2.7.4-1ubuntu0.2
libexpat1 2.7.4-1ubuntu0.2
libexpat1-dev 2.7.4-1ubuntu0.2
Ubuntu 24.04 LTS
expat 2.6.1-2ubuntu0.6
libexpat1 2.6.1-2ubuntu0.6
libexpat1-dev 2.6.1-2ubuntu0.6
Ubuntu 22.04 LTS
expat 2.4.7-1ubuntu0.9
libexpat1 2.4.7-1ubuntu0.9
libexpat1-dev 2.4.7-1ubuntu0.9
Ubuntu 20.04 LTS
expat 2.2.9-1ubuntu0.8+esm3
Available with Ubuntu Pro
libexpat1 2.2.9-1ubuntu0.8+esm3
Available with Ubuntu Pro
libexpat1-dev 2.2.9-1ubuntu0.8+esm3
Available with Ubuntu Pro
Ubuntu 18.04 LTS
expat 2.2.5-3ubuntu0.9+esm5
Available with Ubuntu Pro
libexpat1 2.2.5-3ubuntu0.9+esm5
Available with Ubuntu Pro
libexpat1-dev 2.2.5-3ubuntu0.9+esm5
Available with Ubuntu Pro
Ubuntu 16.04 LTS
expat 2.1.0-7ubuntu0.16.04.5+esm14
Available with Ubuntu Pro
lib64expat1 2.1.0-7ubuntu0.16.04.5+esm14
Available with Ubuntu Pro
lib64expat1-dev 2.1.0-7ubuntu0.16.04.5+esm14
Available with Ubuntu Pro
libexpat1 2.1.0-7ubuntu0.16.04.5+esm14
Available with Ubuntu Pro
libexpat1-dev 2.1.0-7ubuntu0.16.04.5+esm14
Available with Ubuntu Pro
Ubuntu 14.04 LTS
expat 2.1.0-4ubuntu1.4+esm13
Available with Ubuntu Pro
lib64expat1 2.1.0-4ubuntu1.4+esm13
Available with Ubuntu Pro
lib64expat1-dev 2.1.0-4ubuntu1.4+esm13
Available with Ubuntu Pro
libexpat1 2.1.0-4ubuntu1.4+esm13
Available with Ubuntu Pro
libexpat1-dev 2.1.0-4ubuntu1.4+esm13
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8813-1
CVE-2026-56131, CVE-2026-56132, CVE-2026-56406, CVE-2026-56407,
CVE-2026-56409, CVE-2026-56410, CVE-2026-56411, CVE-2026-66046,
CVE-2026-72522, CVE-2026-76641, CVE-2026-76957
Package Information:
https://launchpad.net/ubuntu/+source/expat/2.7.4-1ubuntu0.2
https://launchpad.net/ubuntu/+source/expat/2.6.1-2ubuntu0.6
https://launchpad.net/ubuntu/+source/expat/2.4.7-1ubuntu0.9
--===============5872213748394138006==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
