CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

DSA-6446-1 expat - security update

highCVE-2026-72522
A flaw was discovered in the UTF-16 decoding support of expat, an XML parsing C library, where low surrogates were treated in the same way as high surrogates. Parsing crafted XML input may result in an out-of-bounds read and a resultant infinite loop, leading to denial of service. Only builds with 16 bit character support are affected, which in Debian is the libexpatw library shipped in the libexpat1 package. In addition, this update corrects a regression introduced in the previous security update (DSA-6404-1): on 32 bit architectures, documents larger than 2 GiB were incorrectly rejected with an out of memory error. https://security-tracker.debian.org/tracker/DSA-6446-1

CSIRTS triage

What
A UTF-16 decoding flaw in expat causes low surrogates to be treated as high surrogates, resulting in out-of-bounds read and infinite loop denial of service.
Who is affected
Systems using expat with 16-bit character support (libexpatw in Debian) are affected.
Urgency
High urgency; out-of-bounds read leading to infinite loop can crash XML parsing applications.
Action
Update expat to DSA-6446-1 or later to fix the UTF-16 decoding flaw and regression.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch expat

Get an email when a new expat advisory drops — max one per day, one-click unsubscribe.

Details

Source
Debian Security Advisories (INTL · vendor-psirt · site)
Severity
high
Published
2026-08-18
Exploitation
Not in CISA KEV at last sync

Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00357.html

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-72522coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Debian Security Advisories