Advisories ยป MGASA-2026-0061

Updated expat packages fix security vulnerabilities

Publication date: 20 Mar 2026
Modification date: 20 Mar 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-32776 , CVE-2026-32777 , CVE-2026-32778

Description

libexpat before 2.7.5 allows a NULL pointer dereference with empty
external parameter entity content. (CVE-2026-32776)
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
(CVE-2026-32777)
libexpat before 2.7.5 allows a NULL pointer dereference in the function
setContext on retry after an earlier out-of-memory condition.
(CVE-2026-32778)
                

References

SRPMS

9/core