CVE-2026-77214

high
Assigned by CNA: vulncheck
Published 2026-10-07 · Modified 2026-10-07
CVSS v3
8.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
CVSS v4 NEW
8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
VIR risk
8.2

Description

libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives.

Predictions

Exploit likelihood
88%
Patch ETA
—

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-77214 NameCVE-2026-77214 SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source PackageReleaseVersionStatus expat (PTS)bookworm2.5.0-1+deb12u2vulnerable bookworm…

CVE-2026-77214

NameCVE-2026-77214
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
expat (PTS)bookworm2.5.0-1+deb12u2vulnerable
bookworm (security)2.5.0-1+deb12u4vulnerable
trixie (security), trixie2.8.3-1~deb13u1vulnerable
forky2.8.4-2vulnerable
sid2.8.5-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
expatsource(unstable)2.9.0-1

Notes

https://github.com/libexpat/libexpat/pull/1393
Fixed by: https://github.com/libexpat/libexpat/commit/4d9b1c499ecb66323260a7274edcf86c5eab0517 (R_2_9_0)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://github.com/libexpat/libexpat/pull/1393Fixed by: https://github.com/libexpat/libexpat/commit/4d9b1c499ecb66323260a7274edcf86c5eab0517 (R_2_9_0)

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
— Affected —
debian Debian Mixed 4 releases
VersionStatusFixed in
trixie Affected —
sid Fixed 2.9.0-1
forky Affected —
bookworm Affected —

References

CWEs

CWE-125

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.