Fedora 43 and 44 mingw-expat Denial of Service Vulnerability Update

Fedora 43 and 44 mingw-expat Denial of Service Vulnerability Update

First seen 3 Sep 2026, 07:29 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

Fedora has released updates for mingw-expat to address a Denial of Service vulnerability identified as CVE-2026-72522. This vulnerability arises from improper handling of Unicode surrogate pairs, potentially allowing attackers to disrupt services. The affected versions are expat-2.8.2 and earlier, with the patched version being expat-2.8.3. Users are advised to upgrade to the latest version to mitigate the risk. The vulnerability was published on August 10, 2026, and is applicable to all Fedora systems utilizing mingw-expat. The updates can be installed using the 'dnf' update program. The issue was reported under Bug #2513993, indicating a broad scope of impact across Fedora installations. Current status shows that the vulnerability has been patched, but administrators are urged to apply the updates promptly.

Key Points: • CVE-2026-72522 affects mingw-expat in Fedora 43 and 44. • Denial of Service vulnerability due to incorrect Unicode handling. • Users must upgrade to expat-2.8.3 to mitigate risks.

Timeline

2026-08-10
CVE-2026-72522 published
Denial of Service vulnerability in mingw-expat due to improper Unicode surrogate handling disclosed.
Linuxsecurity
2026-08-25
Fedora updates released
Fedora released updates to expat-2.8.3 to address CVE-2026-72522, urging users to upgrade.
Linuxsecurity
Recent
Patching guidance issued
Administrators are advised to apply the latest patches to mitigate the Denial of Service risk.
Linuxsecurity