Skip to content

CVE-2026-72522 on CTRL-OS 26.05

Aliases: CVE-2026-72522

Packages: expat

Status: In Progress

Advisory Information

libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.

Updates

2026-08-12 17:26 CEST

Metadata changes:

  • Status for package expat: “In Progress” (2a1b1e76e5e2e719f11ac778f2934f32738cb846)

2026-08-12 17:26 CEST

Metadata changes:

  • Status for package expat: “New” (2a1b1e76e5e2e719f11ac778f2934f32738cb846)

2026-08-12 17:25 CEST

Metadata changes:

  • Status for package expat: “New