Protection mechanism failure in expat - CVE-2026-56412
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to missing control flow integrity checks in doCdataSection when handling XML_TOK_DATA_CHARS callbacks. A remote attacker can trigger unsafe handler calls to cause memory corruption.
This issue is described as a hole in the fix for CVE-2026-50219.
Affected software
LANTIME Operating System Firmware (LTOS)
openEuler
Anolis OS
Fedora
expat-help
expat-devel
expat-debugsource
expat-debuginfo
expat
expat-doc
expat-static
mingw-expat
How to mitigate CVE-2026-56412
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
expat-help - addressed in versions 2.2.9-28, 2.4.1-27, 2.5.0-22, 2.5.0-23
expat-devel - addressed in versions 2.2.9-28, 2.4.1-27, 2.5.0-22, 2.5.0-23
expat-debugsource - addressed in versions 2.2.9-28, 2.4.1-27, 2.5.0-22, 2.5.0-23
expat-debuginfo - addressed in versions 2.2.9-28, 2.4.1-27, 2.5.0-22, 2.5.0-23
expat - addressed in versions 2.2.9-28, 2.4.1-27, 2.5.0-22, 2.5.0-23
expat-doc - update to 2.5.0-16
expat-static - update to 2.5.0-16
expat-devel - update to 2.5.0-16
expat - update to 2.5.0-16
mingw-expat - addressed in versions 2.8.2-1.fc43, 2.8.2-1.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in libexpat
- Multiple vulnerabilities in Meinberg LANTIME firmware
- Fedora 44 update for mingw-expat
- Fedora 43 update for mingw-expat
- openEuler 24.03 LTS SP3 update for expat
- openEuler 24.03 LTS SP1 update for expat
- openEuler 22.03 LTS SP4 update for expat
- openEuler 20.03 LTS SP4 update for expat
- Anolis OS update for expat