#1148665 expat: CVE-2026-93990

Package:
src:expat
Source:
src:expat
Submitter:
Salvatore Bonaccorso
Date:
2026-09-22 05:23:02 UTC
Severity:
normal
Tags:
#1148665#5
Date:
2026-09-21 18:40:39 UTC
From:
To:
Hi,

The following vulnerability was published for expat.

CVE-2026-93990[0]:
| Expat through 2.8.4 fails to validate low surrogates following high
| surrogates in UTF-16 input, allowing malformed UTF-16 sequences to
| be accepted. Attackers can craft UTF-16 encoded XML with lone high
| surrogates that consume following code units, hiding markup
| characters from the parser and enabling XML injection attacks.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-93990
https://www.cve.org/CVERecord?id=CVE-2026-93990
[1] https://github.com/libexpat/libexpat/pull/1282
[2] https://github.com/libexpat/libexpat/commit/0cfd15bdf4b2c22d6b0df73610709dfb60921091
[3] https://github.com/libexpat/libexpat/commit/28fcfba540f6933aa8904a1514c4811713d2ab72

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1148665#10
Date:
2026-09-22 05:19:10 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
expat, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1148665@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Laszlo Boszormenyi (GCS) <gcs@debian.org> (supplier of updated expat package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 22 Sep 2026 06:48:48 +0200
Source: expat
Architecture: source
Version: 2.8.4-2
Distribution: unstable
Urgency: high
Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Changed-By: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Closes: 1148665
Changes:
 expat (2.8.4-2) unstable; urgency=high
 .
   * Backport upstream fixes for CVE-2026-93990: fails to validate low
     surrogates following high surrogates in UTF-16 input (closes: #1148665).
Checksums-Sha1:
 23aace7fbbc305b892865f21e965e18f1cc1bbbd 1970 expat_2.8.4-2.dsc
 71217daa8963fd4ec3d556d9cf911b403372fdda 17272 expat_2.8.4-2.debian.tar.xz
Checksums-Sha256:
 85085c8874a3f9af59abd9d61d83a1f125e243d2209fd8156ad00fdf288c34d1 1970 expat_2.8.4-2.dsc
 558110a1a2dab94b0807647d3f6a89f00c05ddb80f69a0b2c62a12cb385f44d8 17272 expat_2.8.4-2.debian.tar.xz
Files:
 dc7b14ea20b57c7de16d28831cb579e8 1970 text optional expat_2.8.4-2.dsc
 1432163a03e729254f9f0c2a9783f595 17272 text optional expat_2.8.4-2.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAmqyCxEACgkQ3OMQ54ZM
yL+gAw//XGekjmgg+NuDW8ajnQgHO+PR3N+yC0iz0sYW+BtnxXx7maxb7sXdM+Q5
ddsUzHW39GA7Hh1KClDyLEc1mRBZwWe9wCyAbX5w6Vms98pZ3qw4JgCFysSZ1cAo
QdLi0e1TvsQxICDudSF6bv/U9eG8Zv34ylHZX1CwPs7twCPIgEBUepJ9U1Etlj7b
lMv+6hPafiIvVDzTNZUOyktOFuRAKe1e7ys0SeD3LTneATqkkBQ/bLESRZcYYobA
5Ya7yHgLKYTmxtiyELXBC/aRrhGrbaPekpSpQq8DhK78qIpY7e5tf+imK8+jnHeS
C57oxRVghAXH8w/3pugD2BWt9kzzykIMdzYbLafOavGZROK76fhJUgQMESSRoVO7
QVY7lm4BCo9DRE6qWdjCChEh3SZrBCKzPCMlfyH2DaqbO4qLTym31b3Ifyn/B4kz
bHRA2oVGq7No4bh6qrKaNtwRv5AYx82zvnEZ0R2v0Vn8LqL1+lcQdSqw9SEDcLfd
RJlf97yPB10vk5+9910TEiq7yAuSuNZCKR2fjTOIlryp5JrAJJu2LJ3zbmkTyjlW
6Xo2MWHbJlECcwmaBuVQe7cLUwNWFE71V9UBJGORfwYkOs82mf52CB76Z0DoE5Dx
m2Uxu1axY7+d5DcFVAjngydgCXyE04IdEQioYwfq/ixGjEOYhW4=
=GcEs
-----END PGP SIGNATURE-----