Security News

Cybersecurity news aggregator

🔓
MEDIUM Vulnerabilities Ubuntu Security

USN-8520-1: Expat vulnerability

  • What: Vulnerability in Expat XML parser.
  • Impact: Could lead to denial of service via hash flooding.
Read Full Article →

Ubuntu Security Notices USN-8520-1 USN-8520-1: Expat vulnerability Publication date 9 July 2026 Overview Expat could be made to crash if it received specially crafted input. Releases 16.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages expat - XML parsing C library Details It was discovered that Expat used insufficient entropy when generating hash salt values for its internal hash table. An attacker could use this to craft an XML document that triggers hash flooding, leading to a denial of service. It was discovered that Expat used insufficient entropy when generating hash salt values for its internal hash table. An attacker could use this to craft an XML document that triggers hash flooding, leading to a denial of service. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 16.04 LTS xenial libexpat1 – 2.1.0-7ubuntu0.16.04.5+esm12 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-41080 CVE-2026-41080

Share this article