Description:
libexpat before 2.7.5 allows a NULL pointer dereference with empty
external parameter entity content. (CVE-2026-32776)
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
(CVE-2026-32777)
libexpat before 2.7.5 allows a NULL pointer dereference in the function
setContext on retry after an earlier out-of-memory condition.
(CVE-2026-32778)
- https://bugs.mageia.org/show_bug.cgi?id=35227
- https://www.openwall.com/lists/oss-security/2026/03/17/10
- https://www.cve.org/CVERecord?id=CVE-2026-32776
- https://www.cve.org/CVERecord?id=CVE-2026-32777
- https://www.cve.org/CVERecord?id=CVE-2026-32778
- 9/core/expat-2.7.5-1.mga9
Get the latest Linux and open source security news straight to your inbox.