CVE-2026-72522 on CTRL-OS 26.05
Aliases: CVE-2026-72522
Packages: expat
Status: In Progress
Advisory Information
libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.
Updates
2026-08-12 17:26 CEST
Metadata changes:
- Status for package
expat: “In Progress” (2a1b1e76e5e2e719f11ac778f2934f32738cb846)
2026-08-12 17:26 CEST
Metadata changes:
- Status for package
expat: “New” (2a1b1e76e5e2e719f11ac778f2934f32738cb846)
2026-08-12 17:25 CEST
Metadata changes:
- Status for package
expat: “New”