There are 4 open security issues in bookworm.
1 important issue:
- CVE-2026-25210:
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
2 issues left for the package maintainer to handle:
- CVE-2025-66382:
(postponed; to be fixed through a stable update)
In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
- CVE-2026-24515:
(needs triaging)
In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.
You can find information about how to handle these issues in the security team's documentation.
1 ignored issue:
- CVE-2025-59375:
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.