Your message dated Tue, 11 Aug 2026 05:18:46 +0000
with message-id <[email protected]>
and subject line Bug#1144064: fixed in expat 2.8.3-1
has caused the Debian Bug report #1144064,
regarding expat: CVE-2026-72522
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1144064: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144064
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: expat
Version: 2.8.2-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/libexpat/libexpat/pull/1296
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for expat.

CVE-2026-72522[0]:
| libexpat before 2.8.3 has an out-of-bounds read and resultant
| infinite loop because low surrogates are treated the same as high
| surrogates during Unicode processing in the *_toUtf16 functions.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-72522
    https://www.cve.org/CVERecord?id=CVE-2026-72522
[1] https://github.com/libexpat/libexpat/pull/1296

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: expat
Source-Version: 2.8.3-1
Done: Laszlo Boszormenyi (GCS) <[email protected]>

We believe that the bug you reported is fixed in the latest version of
expat, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Laszlo Boszormenyi (GCS) <[email protected]> (supplier of updated expat package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 11 Aug 2026 06:52:38 +0200
Source: expat
Architecture: source
Version: 2.8.3-1
Distribution: unstable
Urgency: high
Maintainer: Laszlo Boszormenyi (GCS) <[email protected]>
Changed-By: Laszlo Boszormenyi (GCS) <[email protected]>
Closes: 1144064
Changes:
 expat (2.8.3-1) unstable; urgency=high
 .
   * New upstream release:
     - fixes CVE-2026-72522: out of bounds read and resultant infinite loop
       (closes: #1144064).
Checksums-Sha1:
 9f39ca05bc198eed87de1a820d921da6501c4c7a 1970 expat_2.8.3-1.dsc
 634727e5c97647ddaa90687d33e3a8324d317fcc 8464226 expat_2.8.3.orig.tar.gz
 0f54354b7369520339e8a539a82a2c4fc5e844e1 14044 expat_2.8.3-1.debian.tar.xz
Checksums-Sha256:
 234090d3535cfceb09f61b9f97d14f8a0afe51f04bd26a077bc83092543f9ab3 1970 
expat_2.8.3-1.dsc
 533659a16e0184035a99fd8e783f1ad61a887a7bf8586a8681740b9d7ed42389 8464226 
expat_2.8.3.orig.tar.gz
 c9817a59c9f9a56b689651a38e94d6ac403eb19e7146af76bd29f081948a443e 14044 
expat_2.8.3-1.debian.tar.xz
Files:
 62305e3c61d8186f6996f7360b4053a9 1970 text optional expat_2.8.3-1.dsc
 63cb21352b02ab04011d0b49c0e11ec6 8464226 text optional expat_2.8.3.orig.tar.gz
 6ef3c503b7686bc9fcf44edeebe4d8a2 14044 text optional 
expat_2.8.3-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAmp6q+0ACgkQ3OMQ54ZM
yL8r7g/+JLVg5N6fek1fUNeBtDQJjOE+ISwA2Zt4KYrlwH69MgKR07iZGexhL6z/
y/ph2xRPnFYkWiKTDzelO0drNuOvJwE5ijq5RQ3VIE7i+ZIYiimDLCCwG/bWx2jS
uk0FBYd12RD5loZ+J1Do9/Fo1cbRercyLeIUD9WwtOWXUvDv4MGsZbBdUs+OFgC/
6eaRFS6bdMeCvYGRIDdqRhYdCSoRke+5eQhP1avHQCqs/dmId/pyuHMSM3bcO1Se
YquluP1NKEc9bLmclyAaRIgboM1D0TYwT+akX2gvc4NwgZpTHQa1f7XTdPYIAMK5
gQcnkpiANF0bGd1xwpoKtv0Dbh/uGxW0RSFRKbAyKhboYWUi1gBKRXd7Yr8y0GDK
bTgVWuFMtw1+JWd/vgfSl8w9FwRsWmgVFKERq76+O2ZUQqioX6mKYZOtTcd5QeOq
n97TqDzovULoinLASD2yyGC/ttFOY0QO8w0ANpINYpPrOGMU8DTe632h1gQarZ7n
51eLV2VZ7Ic6WpgL4zcY8G+SjmrKhb5DDPkMMtIBXqk3zUVFmvtv/QpYr/0pAwjK
tULhDfGNMZaZDPJdxL+qAVMHXuw5YHKKMFL8YeGKp1iPjlvOJWHEVRnqbsh0OgVC
MoTU6P0iEcxNTWymyktW9+icr395hyknHwm9gbmg1UUWVwQCTI0=
=Nk3b
-----END PGP SIGNATURE-----

Attachment: pgpw67OMoJzFd.pgp
Description: PGP signature


--- End Message ---

Reply via email to