NULL pointer dereference in expat - CVE-2026-32778
Published: March 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in the function setContext in libexpat when processing XML input under low-memory conditions. A remote attacker can send a specially crafted XML file to cause a denial of service.
Exploitation requires repeated processing of malicious input following an initial out-of-memory condition.
Affected software
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Desktop Applications Module
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
openEuler
Anolis OS
iDRAC9
WebSphere Remote Server
IBM Rational ClearQuest
IBM Business Automation Workflow
IBM HTTP Server
IBM OpenPages with Watson
Integrated System for Microsoft Azure Stack Hub
expat
expat-devel
expat-static
expat-doc
expat-help
expat-debugsource
expat-debuginfo
libexpat-devel
libexpat1-debuginfo
libexpat1-debuginfo-32bit
libexpat1-32bit
expat-debuginfo-32bit
libexpat1
expat-64bit-debuginfo
libexpat1-64bit
libexpat1-64bit-debuginfo
libexpat-devel-64bit
libexpat-devel-32bit
expat-32bit-debuginfo
libexpat1-32bit-debuginfo
libmozjs-52-debuginfo
mozjs52-debuginfo
mozjs52-debugsource
libmozjs-52
mozjs60-devel
libmozjs-60
libmozjs-60-debuginfo
mozjs60-debugsource
mozjs60-debuginfo
libmozjs-78-0
mozjs78-debugsource
mozjs78-debuginfo
mozjs78
libmozjs-78-0-debuginfo
mozjs78-devel
mozjs115-devel
mozjs115-debugsource
libmozjs-115-0-debuginfo
mozjs115-debuginfo
libmozjs-115-0
mozjs115
Encryption Admin Utilities
How to mitigate CVE-2026-32778
iDRAC9 - addressed in versions 7.00.00.184, 7.30.30.51
IBM HTTP Server - addressed in versions 8.5.5.30, 9.0.5.28
expat - update to 2.5.0-12
expat-devel - update to 2.5.0-12
expat-static - update to 2.5.0-12
expat-doc - update to 2.5.0-12
expat - update to 2.5.0-16
expat-help - update to 2.5.0-16
expat-devel - update to 2.5.0-16
expat-debugsource - update to 2.5.0-16
expat-debuginfo - update to 2.5.0-16
libexpat-devel - addressed in versions 2.7.1-21.52.1, 2.7.1-150400.3.37.1, 2.7.1-150700.3.12.1
expat-debuginfo - addressed in versions 2.7.1-21.52.1, 2.7.1-150000.3.45.1, 2.7.1-150400.3.37.1, 2.7.1-150700.3.12.1
libexpat1-debuginfo - addressed in versions 2.7.1-21.52.1, 2.7.1-150000.3.45.1, 2.7.1-150400.3.37.1, 2.7.1-150700.3.12.1
libexpat1-debuginfo-32bit - update to 2.7.1-21.52.1
libexpat1-32bit - addressed in versions 2.7.1-21.52.1, 2.7.1-150400.3.37.1, 2.7.1-150700.3.12.1
expat-debuginfo-32bit - update to 2.7.1-21.52.1
expat-debugsource - addressed in versions 2.7.1-21.52.1, 2.7.1-150000.3.45.1, 2.7.1-150400.3.37.1, 2.7.1-150700.3.12.1
expat - addressed in versions 2.7.1-21.52.1, 2.7.1-150400.3.37.1, 2.7.1-150700.3.12.1
libexpat1 - addressed in versions 2.7.1-21.52.1, 2.7.1-150000.3.45.1, 2.7.1-150400.3.37.1, 2.7.1-150700.3.12.1
expat-64bit-debuginfo - update to 2.7.1-150400.3.37.1
libexpat1-64bit - update to 2.7.1-150400.3.37.1
libexpat1-64bit-debuginfo - update to 2.7.1-150400.3.37.1
libexpat-devel-64bit - update to 2.7.1-150400.3.37.1
libexpat-devel-32bit - update to 2.7.1-150400.3.37.1
expat-32bit-debuginfo - addressed in versions 2.7.1-150400.3.37.1, 2.7.1-150700.3.12.1
libexpat1-32bit-debuginfo - addressed in versions 2.7.1-150400.3.37.1, 2.7.1-150700.3.12.1
Encryption Admin Utilities - update to 11.13.1
libmozjs-52-debuginfo - update to 52.6.0-150000.3.12.1
mozjs52-debuginfo - update to 52.6.0-150000.3.12.1
mozjs52-debugsource - update to 52.6.0-150000.3.12.1
libmozjs-52 - update to 52.6.0-150000.3.12.1
mozjs60-devel - update to 60.9.0-150200.6.11.1
libmozjs-60 - update to 60.9.0-150200.6.11.1
libmozjs-60-debuginfo - update to 60.9.0-150200.6.11.1
mozjs60-debugsource - update to 60.9.0-150200.6.11.1
mozjs60-debuginfo - update to 60.9.0-150200.6.11.1
libmozjs-78-0 - update to 78.15.0-150400.3.17.1
mozjs78-debugsource - update to 78.15.0-150400.3.17.1
mozjs78-debuginfo - update to 78.15.0-150400.3.17.1
mozjs78 - update to 78.15.0-150400.3.17.1
libmozjs-78-0-debuginfo - update to 78.15.0-150400.3.17.1
mozjs78-devel - update to 78.15.0-150400.3.17.1
mozjs115-devel - addressed in versions 115.4.0-150600.3.12.5, 115.4.0-150600.3.14.1
mozjs115-debugsource - addressed in versions 115.4.0-150600.3.12.5, 115.4.0-150600.3.14.1
libmozjs-115-0-debuginfo - addressed in versions 115.4.0-150600.3.12.5, 115.4.0-150600.3.14.1
mozjs115-debuginfo - addressed in versions 115.4.0-150600.3.12.5, 115.4.0-150600.3.14.1
libmozjs-115-0 - addressed in versions 115.4.0-150600.3.12.5, 115.4.0-150600.3.14.1
mozjs115 - addressed in versions 115.4.0-150600.3.12.5, 115.4.0-150600.3.14.1
Integrated System for Microsoft Azure Stack Hub - update to 2606
External References
Related Security Bulletins
- Multiple DoS vulnerabilities in libexpat
- SUSE update for expat
- SUSE update for expat
- Multiple vulnerabilities in IBM HTTP Server
- SUSE update for expat
- openEuler update for expat
- Anolis OS update for expat
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM WebSphere Remote Server
- SUSE update for expat
- SUSE update for mozjs52
- SUSE update for mozjs60
- SUSE update for mozjs115
- SUSE update for mozjs78
- Multiple vulnerabilities in IBM OpenPages
- Multiple vulnerabilities in IBM Rational ClearQuest
- Multiple vulnerabilities in Dell iDRAC9
- Multiple vulnerabilities in Dell Integrated System for Microsoft Azure Stack Hub 14G and 16G
- Multiple vulnerabilities in Dell Encryption