#1150320 expat: CVE-2026-77214 (heap over-read in XML_ParseBuffer) fixed in sid, still open in trixie

Package:
src:expat
Source:
src:expat
Submitter:
Maksimtech Security
Date:
2026-10-08 19:31:04 UTC
Severity:
normal
Tags:
#1150320#5
Date:
2026-10-08 14:56:36 UTC
From:
To:
Dear Maintainer,

CVE-2026-77214 is a heap buffer over-read in libexpat's xmlparse.c:
XML_ParseBuffer advances m_bufferEnd by a caller-supplied length that is
not checked against the allocated buffer, so repeated calls move the end
past the allocation and later parsing reads out of bounds, disclosing
adjacent heap memory (heap, libc and code pointers).

Fixed upstream in R_2_9_0:
   https://github.com/libexpat/libexpat/pull/1393
https://github.com/libexpat/libexpat/commit/4d9b1c499ecb66323260a7274edcf86c5eab0517

Status in Debian, from the security tracker on 2026-10-08:
   sid      2.9.0-1            fixed
   forky    2.8.4-2            vulnerable
   trixie   2.8.3-1~deb13u1    vulnerable
   bookworm 2.5.0-1+deb12u4    vulnerable

The tracker records no no-dsa decision and no bug for this CVE, hence this
report. Could the upstream fix be cherry-picked into a trixie (and bookworm)
update? The change is small and self-contained (a length check in
XML_ParseBuffer), and the other expat CVEs currently open in trixie are
tracked in #1148665, so this one could ride along with them.

Why it matters to us: expat is pulled into container images that run a
browser (via libfontconfig1 and Mesa), where every scanner flags it at high
severity with "no fix available" for Debian 13, and the only honest answer
today is a dated exception.

Thank you for your work on Debian.