HomeDefectsLIN1025-8422
Fixed

LIN1025-8422 : Security Advisory - expat - CVE-2026-32778

Created: Mar 17, 2026    Updated: May 10, 2026
Resolved Date: May 7, 2026
Found In Version: 10.25.33.2
Fix Version: 10.25.33.9
Severity: Standard
Applicable for: Wind River Linux LTS 25
Component/s: Userspace

Description

libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.

CVEs