Skip to content
Multiple Use-after-free Vulnerabilities Found in Fedora's mingw-expat

Multiple Use-after-free Vulnerabilities Found in Fedora's mingw-expat

First seen 6 Jul 2026, 23:49 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •July 7, 2026 at 21:39 UTC
  • •Fedora has issued advisories for critical vulnerabilities in the mingw-expat library.
  • •CVE-2026-50219 and CVE-2026-56412 involve use-after-free vulnerabilities.
  • •CVE-2026-56132 allows for arbitrary code execution via a buffer overflow.

Fedora has released advisories for multiple use-after-free vulnerabilities in the mingw-expat library affecting Fedora 43 and 44. CVE-2026-50219, published on 2026-06-04, involves improper handler call depth tracking, while CVE-2026-56412, published on 2026-06-21, pertains to improper handling of XML CDATA sections. Additionally, CVE-2026-56132, published on 2026-06-19, allows arbitrary code execution via a heap-based buffer overflow. These vulnerabilities could potentially lead to severe security risks if exploited. Users are advised to update their systems using the dnf upgrade command provided in the advisories. The vulnerabilities affect all Fedora users relying on the mingw-expat library, highlighting the importance of timely updates for security.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 94d ago How this analysis works

Timeline

2026-06-04
CVE-2026-50219 published
A use-after-free vulnerability due to improper handler call depth tracking was disclosed.
Linuxsecurity
2026-06-19
CVE-2026-56132 published
An arbitrary code execution vulnerability via heap-based buffer overflow was disclosed.
Linuxsecurity
2026-06-21
CVE-2026-56412 published
A use-after-free vulnerability due to improper handling of XML CDATA sections was disclosed.
Linuxsecurity
2026-07-06
Fedora advisories released
Fedora released updates for mingw-expat vulnerabilities, urging users to apply patches immediately.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Fedora and CVE-2026-50219 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed