CVE-2016-5300: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 6.5% chance of exploitation in the next 30 days.

The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
  • Debian Debian Linux: version 8.0 only
  • Google Android: version 4.4.4 only; version 5.0.2 only; version 5.1.1 only; version 6.0 only; version 6.0.1 only
  • Libexpat Project Libexpat: before 2.2.0 (fixed in 2.2.0)

Published 2016-06-16. Last modified 2026-06-17.