SB20261001116 - Ubuntu update for expat



SB20261001116 - Ubuntu update for expat

Published: October 1, 2026

Security Bulletin ID SB20261001116
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 12
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 83% Low 17%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 12 vulnerabilities.


1) Resource exhaustion (CVE-ID: CVE-2025-59375)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger large dynamic memory allocations via a small document and perform a denial of service (DoS) attack.


2) NULL Pointer Dereference (CVE-ID: CVE-2026-32776)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in the XML parser when processing malicious XML content with empty external parameter entity content. A remote attacker can send a specially crafted XML file to cause a denial of service.


3) Infinite loop (CVE-ID: CVE-2026-32777)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an infinite loop in the DTD content parser when processing a specially crafted XML file. A remote attacker can send a specially crafted request to cause a denial of service.


4) NULL pointer dereference (CVE-ID: CVE-2026-32778)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in the function setContext in libexpat when processing XML input under low-memory conditions. A remote attacker can send a specially crafted XML file to cause a denial of service.

Exploitation requires repeated processing of malicious input following an initial out-of-memory condition.


5) Inefficient algorithmic complexity (CVE-ID: CVE-2026-45186)

CWE-ID: CWE-407 - Inefficient Algorithmic Complexity

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to computational complexity of attribute name collision checks. A remote attacker can pass specially crafted XML input to the application and perform a denial of service attack.


6) Insufficient entropy (CVE-ID: CVE-2026-41080)

CWE-ID: CWE-331 - Insufficient Entropy

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to insufficient entropy. A remote attacker can supply a specially crafted XML document and flood hashes, leading to a denial of service condition. 


7) Protection mechanism failure (CVE-ID: CVE-2026-50219)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to missing control flow integrity checks in XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, and XML_ParserReset when these functions are called reentrantly from bindings or callbacks. A remote attacker can trigger unsafe parser API calls to cause memory corruption.

The issue is described as relevant to language bindings.


8) Protection mechanism failure (CVE-ID: CVE-2026-56412)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to missing control flow integrity checks in doCdataSection when handling XML_TOK_DATA_CHARS callbacks. A remote attacker can trigger unsafe handler calls to cause memory corruption.

This issue is described as a hole in the fix for CVE-2026-50219.


9) Integer overflow (CVE-ID: CVE-2026-56403)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to an integer overflow in storeAtts when parsing XML attributes. A remote attacker can supply crafted XML input to cause memory corruption.


10) Integer overflow (CVE-ID: CVE-2026-56404)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to an integer overflow in addBinding when processing XML data. A remote attacker can supply crafted XML input to cause memory corruption.


11) Integer overflow (CVE-ID: CVE-2026-56405)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to an integer overflow in getAttributeId when parsing XML attributes. A remote attacker can supply crafted XML input to cause memory corruption.


12) Integer overflow (CVE-ID: CVE-2026-56408)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to an integer overflow in copyString when copying string data. A remote attacker can supply crafted XML input to cause memory corruption.


Remediation

Install update from vendor's website.