Ubuntu alert USN-8022-2 (expat)
| From: | noreply+usn-bot@canonical.com | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8022-2] Expat vulnerabilities | |
| Date: | Mon, 16 Feb 2026 13:32:36 +0000 | |
| Message-ID: | <E1vryiK-0000il-9D@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-8022-2 February 16, 2026 expat vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in Expat. Software Description: - expat: XML parsing C library Details: USN-8022-1 fixed vulnerabilities in Expat. This update provides the corresponding updates for Ubuntu 24.04 LTS. Original advisory details: It was discovered that Expat incorrectly handled the initialization of parsers for external entities. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-24515) It was discovered that Expat incorrectly handled integer calculations when allocating memory for XML tags. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-25210) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS expat 2.6.1-2ubuntu0.4 libexpat1 2.6.1-2ubuntu0.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8022-2 https://ubuntu.com/security/notices/USN-8022-1 CVE-2026-24515, CVE-2026-25210 Package Information: https://launchpad.net/ubuntu/+source/expat/2.6.1-2ubuntu0.4
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmmTG6YACgkQcpJm3tlz hgHhCxAAu+houqtfhFK/+mafvnnm6xVEiwVWeFUksHx1C5YAW8czX9VRI6a8GZ+t RjcH7ZUZA7O++PyS5Aoch/UQiVWIXtGinIbDQC3dKpdqnkexyIJiGeobviRIpIMG K3yNCjaaf6uwrIl80PG208appMZ6UUl+52cHqXut7S6E8zxYKuxbmjxnrgnXSsM8 R+gt1cGGE9JZ4SBZv5DugP3JW0WXOBvwba6kNKs4sGPFIFuqfkDH32YBrlx6QuC1 k+Fhd/qtaJg3saUluneTGvAWgPx7FnNdfwPvHyEnGUNxYsbj55auImWNCayaDaSY GDz4r4lW5tpPym1/3g3Un1SoG4e2D/PQaQYNrbQMOI3KCpCc6C/yHx2d1ZY+1hsZ 8LT2NRyT80QEhuDR14VmCivaQpn7rXZJhoG+FcVVeZmCcVHznDtU5iN9f43gRREK DenAUr8CH+oQXgmPXzcTA/iMSwuneC0IBqO0nZvJijfg7z2NKaJsuCQ2ewYFlrmD pNFKfB8x7+hyPQ4Gvgn7M3HSy5ftZ/OtRKkk9JTIDPzv6cdXg0wgFJMgLxIDgzl6 9SOXF8a3mcHOtXDKA7EeqlOgkI0sNhZjJu90fYjyCgj8xrUxQ69FNd/uJ77WSnVo Okx20vkC0OL8p2oadonMoCkR9jzJotAAgkZAx4RYHtiaMWc4hpE= =C4jq -----END PGP SIGNATURE-----
