USN-8790-1: Expat vulnerabilities
It was discovered that Expat could be made to allocate large amounts of
memory when parsing a small crafted document. An attacker could possibly
use this issue to cause Expat to consume resources, leading to a denial of
service. This issue was only addressed in Ubuntu 24.04 LTS.
(CVE-2025-59375)
It was discovered that Expat incorrectly handled empty external parameter
entity content. An attacker could possibly use this issue to cause Expat to
crash, resulting in a denial of service. (CVE-2026-32776)
It was discovered that Expat incorrectly handled certain DTD content. An
attacker could possibly use this issue to cause Expat to enter an infinite
loop, resulting in a denial of service. (CVE-2026-32777)
It was discovered that Expat incorrectly handled memory when retrying after
an earlier out-of-memory condition. An attacker could possibly use this
issue to cause Expat to crash, resulting in a denial of service.
(CVE-2026-32778)
It was discovered that Expat performed attribute name collision checks
inefficiently. An attacker could possibly use this issue to cause Expat to
consume resources when processing a moderately sized crafted XML document,
resulting in a denial of service. This issue was only addressed in Ubuntu
24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-45186)
It was discovered that Expat used insufficient entropy, allowing hash
flooding through a crafted XML document. An attacker could possibly use
this issue to cause Expat to consume resources, leading to a denial of
service. This issue was only addressed in Ubuntu 14.04 LTS, Ubuntu 24.04
LTS, and Ubuntu 26.04 LTS. (CVE-2026-41080)
It was discovered that Expat did not track handler call depth for certain
functions called from within handlers, leading to a use-after-free. An
attacker could possibly use this issue to cause Expat to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2026-50219, CVE-2026-56412)
It was discovered that Expat incorrectly handled certain values, leading to
integer overflows. An attacker could possibly use this issue to cause Expat
to crash, resulting in a denial of service. (CVE-2026-56403,
CVE-2026-56404, CVE-2026-56405)
It was discovered that Expat incorrectly handled certain values, leading to
an integer overflow. An attacker could possibly use this issue to cause
Expat to crash, resulting in a denial of service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and
Ubuntu 26.04 LTS. (CVE-2026-56408)