{"id":"SUSE-SU-2026:23912-1","summary":"Security update for expat","details":"This update for expat fixes the following issues:\n\n- CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263).\n- CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a\n  denial of service via moderately sized crafted XML input (bsc#1264713).\n- CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse,\n  XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631).\n- CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within\n  handlers in cases of a policy violation (bsc#1268572).\n- CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer\n  overflows (bsc#1268573).\n- CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code\n  execution (bsc#1275096).\n- CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory\n  corruption, and application crashes (bsc#1275096).\n- CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary\n  code execution (bsc#1275096).\n- CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and\n  application crashes (bsc#1275096).\n- CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial\n  of service (bsc#1275096).\n- CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes\n  (bsc#1275096).\n- CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and\n  arbitrary file write conditions (bsc#1275096).\n- CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information\n  disclosure, and potential code execution (bsc#1275096).\n- CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and\n  denial of service (bsc#1275096).\n- CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free\n  conditions and arbitrary code execution (bsc#1275096).\n- CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the\n  storeAtts() function in xmlparse.c (bsc#1275732).\n- CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same\n  as high surrogates during Unicode processing (bsc#1275594).\n- CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger\n  memory corruption (bsc#1275915).\n- CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to\n  insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via\n  crafted X (bsc#1275860).\n- CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859).\n\nChanges for expat:\n\n- Updated to version 2.8.4\n","modified":"2026-09-30T18:23:13.519572564Z","published":"2026-09-24T07:07:13Z","related":["CVE-2026-41080","CVE-2026-45186","CVE-2026-50219","CVE-2026-56131","CVE-2026-56132","CVE-2026-56403","CVE-2026-56404","CVE-2026-56405","CVE-2026-56406","CVE-2026-56407","CVE-2026-56408","CVE-2026-56409","CVE-2026-56410","CVE-2026-56411","CVE-2026-56412","CVE-2026-66046","CVE-2026-72522","CVE-2026-76641","CVE-2026-76956","CVE-2026-76957"],"upstream":["CVE-2026-41080","CVE-2026-45186","CVE-2026-50219","CVE-2026-56131","CVE-2026-56132","CVE-2026-56403","CVE-2026-56404","CVE-2026-56405","CVE-2026-56406","CVE-2026-56407","CVE-2026-56408","CVE-2026-56409","CVE-2026-56410","CVE-2026-56411","CVE-2026-56412","CVE-2026-66046","CVE-2026-72522","CVE-2026-76641","CVE-2026-76956","CVE-2026-76957"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623912-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262263"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264713"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267631"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268572"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268573"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275096"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275594"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275732"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275859"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275860"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275915"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41080"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45186"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50219"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56131"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56132"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56403"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56404"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56405"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56406"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56407"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56409"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56410"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56411"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56412"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-66046"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-72522"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76641"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76956"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76957"}],"affected":[{"package":{"name":"expat","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/expat&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.4-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"expat":"2.8.4-160000.1.1","libexpat-devel":"2.8.4-160000.1.1","libexpat1":"2.8.4-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23912-1.json"}},{"package":{"name":"expat","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/expat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.4-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"libexpat-devel":"2.8.4-160000.1.1","libexpat1":"2.8.4-160000.1.1","expat":"2.8.4-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23912-1.json"}}],"schema_version":"1.9.0"}