Bug 2520124 (CVE-2026-76956) - CVE-2026-76956 libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML
Summary: CVE-2026-76956 libexpat: libexpat: Denial of Service via hash flooding attack...
Keywords:
Status: NEW
Alias: CVE-2026-76956
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2524647
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-20 04:41 UTC by OSIDB Bzimport
Modified: 2026-08-26 19:39 UTC (History)
27 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-20 04:41:17 UTC
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.


Note You need to log in before you can comment on or make changes to this bug.