Skip to content

CVE-2026-93990 on Cyberus Linux 26.05

Aliases: CVE-2026-93990

Packages: expat

Status: Resolved

Advisory Information

Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds.

Updates

2026-10-09 02:49 CEST

Metadata changes:

  • Status for package expat: “Resolved” (ab015e382a111c2a3b28a6b7718584fd50d7752e)

2026-09-28 21:41 CEST

Metadata changes:

  • Status for package expat: “In Progress” (ab015e382a111c2a3b28a6b7718584fd50d7752e)

(Amended on: 2026-09-28 21:42 CEST)

2026-09-24 17:31 CEST

Metadata changes:

  • Status for package expat: “Plausible”

2026-09-24 17:29 CEST

Metadata changes:

  • Status for package expat: “New”