Dear Maintainer, CVE-2026-77214 is a heap buffer over-read in libexpat's xmlparse.c: XML_ParseBuffer advances m_bufferEnd by a caller-supplied length that is not checked against the allocated buffer, so repeated calls move the end past the allocation and later parsing reads out of bounds, disclosing adjacent heap memory (heap, libc and code pointers). Fixed upstream in R_2_9_0: https://github.com/libexpat/libexpat/pull/1393 https://github.com/libexpat/libexpat/commit/4d9b1c499ecb66323260a7274edcf86c5eab0517 Status in Debian, from the security tracker on 2026-10-08: sid 2.9.0-1 fixed forky 2.8.4-2 vulnerable trixie 2.8.3-1~deb13u1 vulnerable bookworm 2.5.0-1+deb12u4 vulnerable The tracker records no no-dsa decision and no bug for this CVE, hence this report. Could the upstream fix be cherry-picked into a trixie (and bookworm) update? The change is small and self-contained (a length check in XML_ParseBuffer), and the other expat CVEs currently open in trixie are tracked in #1148665, so this one could ride along with them. Why it matters to us: expat is pulled into container images that run a browser (via libfontconfig1 and Mesa), where every scanner flags it at high severity with "no fix available" for Debian 13, and the only honest answer today is a dated exception. Thank you for your work on Debian.