PT-2026-78884 · Canonical+7 · Ayttm+16

CVE-2026-76957

·

Publicado

2026-08-20

·

Atualizado

2026-09-09

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.

Exploit

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-96851
CVE-2026-76957
ECHO-7A51-5EF2-DA43
OPENSUSE-SU-2026:11733-1

Produtos afetados

Ayttm
Cableswig
Cadaver
Coin3
Expat
Gdcm
Insighttoolkit4
Libexpat
Libxmltok
Matanza
Smart
Swish-E
Tdom
Vnc4
Vtk
Wbxml2
Xmlrpc-C