Protection mechanism failure in expat - CVE-2026-56131
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to missing control flow integrity checks in XML_ResumeParser when it is called from a handler. A remote attacker can trigger a handler-driven call to XML_ResumeParser to cause memory corruption.
This issue is described as a hole in the fix for CVE-2026-50219.
Affected software
LANTIME Operating System Firmware (LTOS)
openEuler
expat-help
expat-devel
expat-debugsource
expat-debuginfo
expat
How to mitigate CVE-2026-56131
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
expat-help - addressed in versions 2.2.9-27, 2.4.1-26, 2.5.0-21
expat-devel - addressed in versions 2.2.9-27, 2.4.1-26, 2.5.0-21
expat-debugsource - addressed in versions 2.2.9-27, 2.4.1-26, 2.5.0-21
expat-debuginfo - addressed in versions 2.2.9-27, 2.4.1-26, 2.5.0-21
expat - addressed in versions 2.2.9-27, 2.4.1-26, 2.5.0-21