Updated expat packages fix security vulnerabilities
Publication date: 20 Mar 2026Modification date: 20 Mar 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-32776 , CVE-2026-32777 , CVE-2026-32778
Description
libexpat before 2.7.5 allows a NULL pointer dereference with empty
external parameter entity content. (CVE-2026-32776)
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
(CVE-2026-32777)
libexpat before 2.7.5 allows a NULL pointer dereference in the function
setContext on retry after an earlier out-of-memory condition.
(CVE-2026-32778)
References
SRPMS
9/core
- expat-2.7.5-1.mga9