DSA-6446-1 expat - security update
A flaw was discovered in the UTF-16 decoding support of expat, an XML parsing C library, where low surrogates were treated in the same way as high surrogates. Parsing crafted XML input may result in an out-of-bounds read and a resultant infinite loop, leading to denial of service. Only builds with 16 bit character support are affected, which in Debian is the libexpatw library shipped in the libexpat1 package. In addition, this update corrects a regression introduced in the previous security update (DSA-6404-1): on 32 bit architectures, documents larger than 2 GiB were incorrectly rejected with an out of memory error. https://security-tracker.debian.org/tracker/DSA-6446-1
CSIRTS triage
- What
- A UTF-16 decoding flaw in expat causes low surrogates to be treated as high surrogates, resulting in out-of-bounds read and infinite loop denial of service.
- Who is affected
- Systems using expat with 16-bit character support (libexpatw in Debian) are affected.
- Urgency
- High urgency; out-of-bounds read leading to infinite loop can crash XML parsing applications.
- Action
- Update expat to DSA-6446-1 or later to fix the UTF-16 decoding flaw and regression.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch expat
Get an email when a new expat advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00357.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-725220.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-72522 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] expat: Vulnerability enables denial of servicecert-bund
- mediumCVE-2026-72522: libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrog…msrc
- mediumCVE-2026-72522: libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrog…nvd
More from Debian Security Advisories
- unknownDSA-6451-1 firefox-esr - security update2026-08-19
- unknownDSA-6447-1 librabbitmq - security update2026-08-18
- unknownDSA-6450-1 srt - security update2026-08-18
- unknownDSA-6449-1 swift - security update2026-08-18
- unknownDSA-6448-1 spip - security update2026-08-18