Unchecked Return Value in expat - CVE-2026-76956
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inverted getentropy() return handling in the entropy extraction logic when initializing hash randomization. A remote attacker can conduct a hash-flooding attack to cause a denial of service.
The issue applies where getentropy is configured or detected as the only high-quality entropy extractor.
Affected software
Fedora
mingw-expat
How to mitigate CVE-2026-76956
mingw-expat - addressed in versions 2.8.4-1.fc43, 2.8.4-1.fc44, 2.8.4-1.fc45