Debian LTS Security Updates Address Critical Vulnerabilities in Expat and Libass

Debian LTS Security Updates Address Critical Vulnerabilities in Expat and Libass

First seen 2 Sep 2026, 19:43 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

Debian has released security updates for two libraries, Expat and Libass, addressing multiple vulnerabilities. The Expat library has several CVEs, including CVE-2026-56403 to CVE-2026-56412, which involve use-after-free issues and integer overflows, potentially leading to denial of service. The Libass library has a critical out-of-bounds read/write vulnerability (CVE-2026-61627) that could also result in a denial of service. Users of Debian 12 (Bookworm) are advised to upgrade to the patched versions: Expat 2.5.0-1+deb12u3 and Libass 1:0.17.1-1+deb12u1. These vulnerabilities could be exploited by attackers to disrupt services or execute arbitrary code. The updates were published on August 31 and September 2, 2026, respectively, with the Expat vulnerabilities being known since June 21, 2026. Administrators are urged to apply these updates promptly to mitigate risks.

Key Points: • Debian has issued critical updates for Expat and Libass libraries. • Multiple CVEs address use-after-free and denial of service vulnerabilities. • Affected users should upgrade to the latest patched versions immediately.

Timeline

2026-06-21
Multiple CVEs for Expat published
CVE-2026-56403 to CVE-2026-56412 disclosed, involving serious vulnerabilities in Expat.
Linuxsecurity
2026-06-21
CVE-2026-56410 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-21
CVE-2026-56412 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-21
CVE-2026-56409 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-21
CVE-2026-56403 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-21
CVE-2026-56407 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-21
CVE-2026-56406 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-21
CVE-2026-56408 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-21
CVE-2026-56411 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-21
CVE-2026-56404 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE