🛡️ SUSE-SU-2025:20207-1 — expat (CVE-2024-8176 +9 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for expat

This update for expat fixes the following issues:

Version update to 2.7.1:

  • Bug fixes:
  • Restore event pointer behavior from Expat 2.6.4 (that the fix to CVE-2024-8176 changed in 2.7.0);

affected API functions are:

  • XML_GetCurrentByteCount
  • XML_GetCurrentByteIndex
  • XML_GetCurrentColumnNumber
  • XML_GetCurrentLineNumber
  • XML_GetInputContext
  • Other changes:

#976 #977 Autotools: Integrate files "fuzz/xml_lpm_fuzzer.{cpp,proto}"

with Automake that were missing from 2.7.0 release tarballs

#983 #984 Fix printf format specifiers for 32bit Emscripten

#992 docs: Promote OpenSSF Best Practices self-certification

#978 tests/benchmark: Resolve mistaken double close

#986 Address compiler warnings

#990 #993 Version info bumped from 11:1:10 (libexpat*.so.1.10.1)

to 11:2:10 (libexpat*.so.1.10.2); see https://verbump.de/

for what these numbers do

Infrastructure:

#982 CI: Start running Perl XML::Parser integration tests

#987 CI: Enforce Clang Static Analyzer clean code

#991 CI: Re-enable warning clang-analyzer-valist.Uninitialized

for clang-tidy

#981 CI: Cover compilation with musl

#983 #984 CI: Cover compilation with 32bit Emscripten

#976 #977 CI: Protect against fuzzer files missing from future

release archives

Version update to 2.7.0 (CVE-2024-8176 [bsc#1239618])

  • Security fixes:
  • CVE-2024-8176 -- Fix crash from chaining a large number

of entities caused by stack overflow by resolving use of

recursion, for all three uses of entities:

  • general entities in character data ("<e>&g1;</e>")
  • general entities in attribute values ("<e k1='&g1;'/>")
  • parameter entities ("%p1;")

Known impact is (reliable and easy) denial of service:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:H/RL:O/RC:C

(Base Score: 7.5, Temporal Score: 7.2)

Please note that a layer of compression around XML can

significantly reduce the minimum attack payload size.

  • Other changes:
  • Document changes since the previous release
  • Version info bumped from 11:0:10 (libexpat*.so.1.10.0)

to 11:1:10 (libexpat*.so.1.10.1); see https://verbump.de/

for what these numbers do

Version update to 2.6.4:

  • Security fixes: [bsc#1232601][bsc#1232579]
  • CVE-2024-50602 -- Fix crash within function XML_ResumeParser

from a NULL pointer dereference by disallowing function

XML_StopParser to (stop or) suspend an unstarted parser.

A new error code XML_ERROR_NOT_STARTED was introduced to

properly communicate this situation. // CWE-476 CWE-754

  • Other changes:
  • Version info bumped from 10:3:9 (libexpat*.so.1.9.3)

to 11:0:10 (libexpat*.so.1.10.0); see https://verbump.de/

for what these numbers do

Update to 2.6.3:

  • Security fixes:
  • CVE-2024-45490, bsc#1229930 -- Calling function XML_ParseBuffer with

len < 0 without noticing and then calling XML_GetBuffer

will have XML_ParseBuffer fail to recognize the problem

and XML_GetBuffer corrupt memory.

With the fix, XML_ParseBuffer now complains with error

XML_ERROR_INVALID_ARGUMENT just like sibling XML_Parse

has been doing since Expat 2.2.1, and now documented.

Impact is denial of service to potentially artitrary code

execution.

  • CVE-2024-45491, bsc#1229931 -- Internal function dtdCopy can have an

integer overflow for nDefaultAtts on 32-bit platforms

(where UINT_MAX equals SIZE_MAX).

Impact is denial of service to potentially artitrary code

execution.

  • CVE-2024-45492, bsc#1229932 -- Internal function nextScaffoldPart can

have an integer overflow for m_groupSize on 32-bit

platforms (where UINT_MAX equals SIZE_MAX).

Impact is denial of service to potentially artitrary code

execution.

  • Other changes:
  • Version info bumped from 10:2:9 (libexpat*.so.1.9.2)

to 10:3:9 (libexpat*.so.1.9.3); see https://verbump.de/

for what these numbers do

Update to 2.6.2:

  • CVE-2024-28757 -- Prevent billion laughs attacks with isolated

use of external parsers (bsc#1221289)

  • Reject direct parameter entity recursion and avoid the related

undefined behavior

Update to 2.6.1:

  • Expose billion laughs API with XML_DTD defined and XML_GE

undefined, regression from 2.6.0

  • Make tests independent of CPU speed, and thus more robust

Update to 2.6.0:

  • Security fixes:
  • CVE-2023-52425 (bsc#1219559)

Fix quadratic runtime issues with big tokens

that can cause denial of service, in partial where

dealing with compressed XML input. Applications

that parsed a document in one go -- a single call to

functions XML_Parse or XML_ParseBuffer -- were not affected.

Affected software

SUSE-SU-2025:20207-1 is recorded against 1 package.

  • expat (fixed in 2.7.1-1.1)

Timeline and source

Published on 29 April 2025 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-04-29
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
expat 2.7.1-1.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:20207-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:20207-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2025