CVE-2026-93990 on Cyberus Linux 26.05
Aliases: CVE-2026-93990
Packages: expat
Status: Resolved
Advisory Information
Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds.
Updates
2026-10-09 02:49 CEST
Metadata changes:
- Status for package
expat: “Resolved” (ab015e382a111c2a3b28a6b7718584fd50d7752e)
2026-09-28 21:41 CEST
Metadata changes:
- Status for package
expat: “In Progress” (ab015e382a111c2a3b28a6b7718584fd50d7752e)
(Amended on: 2026-09-28 21:42 CEST)
2026-09-24 17:31 CEST
Metadata changes:
- Status for package
expat: “Plausible”
2026-09-24 17:29 CEST
Metadata changes:
- Status for package
expat: “New”