🛡️ SUSE-SU-2025:20311-1 — expat (CVE-2024-8176 +9 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for expat

This update for expat fixes the following issues:

Version update to 2.7.1:

Bug fixes:

#980 #989 Restore event pointer behavior from Expat 2.6.4

(that the fix to CVE-2024-8176 changed in 2.7.0);

affected API functions are:

  • XML_GetCurrentByteCount
  • XML_GetCurrentByteIndex
  • XML_GetCurrentColumnNumber
  • XML_GetCurrentLineNumber
  • XML_GetInputContext

Other changes:

#976 #977 Autotools: Integrate files "fuzz/xml_lpm_fuzzer.{cpp,proto}"

with Automake that were missing from 2.7.0 release tarballs

#983 #984 Fix printf format specifiers for 32bit Emscripten

#992 docs: Promote OpenSSF Best Practices self-certification

#978 tests/benchmark: Resolve mistaken double close

#986 Address compiler warnings

#990 #993 Version info bumped from 11:1:10 (libexpat*.so.1.10.1)

to 11:2:10 (libexpat*.so.1.10.2); see https://verbump.de/

for what these numbers do

Infrastructure:

#982 CI: Start running Perl XML::Parser integration tests

#987 CI: Enforce Clang Static Analyzer clean code

#991 CI: Re-enable warning clang-analyzer-valist.Uninitialized

for clang-tidy

#981 CI: Cover compilation with musl

#983 #984 CI: Cover compilation with 32bit Emscripten

#976 #977 CI: Protect against fuzzer files missing from future

release archives

version update to 2.7.0 (CVE-2024-8176 [bsc#1239618]):

  • Security fixes:

#893 #973 CVE-2024-8176 -- Fix crash from chaining a large number

of entities caused by stack overflow by resolving use of

recursion, for all three uses of entities:

  • general entities in character data ("<e>&g1;</e>")
  • general entities in attribute values ("<e k1='&g1;'/>")
  • parameter entities ("%p1;")

Known impact is (reliable and easy) denial of service:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:H/RL:O/RC:C

(Base Score: 7.5, Temporal Score: 7.2)

Please note that a layer of compression around XML can

significantly reduce the minimum attack payload size.

  • Other changes:

#935 #937 Autotools: Make generated CMake files look for

libexpat.@[email protected] on macOS

#925 Autotools: Sync CMake templates with CMake 3.29

#945 #962 #966 CMake: Drop support for CMake <3.13

#942 CMake: Small fuzzing related improvements

#921 docs: Add missing documentation of error code

XML_ERROR_NOT_STARTED that was introduced with 2.6.4

#941 docs: Document need for C++11 compiler for use from C++

#959 tests/benchmark: Fix a (harmless) TOCTTOU

#944 Windows: Fix installer target location of file xmlwf.xml

for CMake

#953 Windows: Address warning -Wunknown-warning-option

about -Wno-pedantic-ms-format from LLVM MinGW

#971 Address Cppcheck warnings

#969 #970 Mass-migrate links from http:// to https://

#947 #958 ..

#974 #975 Document changes since the previous release

#974 #975 Version info bumped from 11:0:10 (libexpat*.so.1.10.0)

to 11:1:10 (libexpat*.so.1.10.1); see https://verbump.de/

for what these numbers do

  • no source changes, just adding jira reference: jsc#SLE-21253

Version update to 2.6.4

  • Security fixes: [bsc#1232601][bsc#1232579]

#915 CVE-2024-50602 -- Fix crash within function XML_ResumeParser

from a NULL pointer dereference by disallowing function

XML_StopParser to (stop or) suspend an unstarted parser.

A new error code XML_ERROR_NOT_STARTED was introduced to

properly communicate this situation. // CWE-476 CWE-754

  • Other changes:

#903 CMake: Add alias target "expat::expat"

#905 docs: Document use via CMake >=3.18 with FetchContent

and SOURCE_SUBDIR and its consequences

#902 tests: Reduce use of global parser instance

#904 tests: Resolve duplicate handler

#317 #918 tests: Improve tests on doctype closing (ex CVE-2019-15903)

#914 Fix signedness of format strings

#919 #920 Version info bumped from 10:3:9 (libexpat*.so.1.9.3)

to 11:0:10 (libexpat*.so.1.10.0); see https://verbump.de/

for what these numbers do

Update to 2.6.3:

  • Security fixes:
  • CVE-2024-45490, bsc#1229930 -- Calling function XML_ParseBuffer with

len < 0 without noticing and then calling XML_G

Affected software

SUSE-SU-2025:20311-1 is recorded against 1 package.

  • expat (fixed in 2.7.1-slfo.1.1_1.1)

Timeline and source

Published on 13 May 2025 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-05-13
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
expat 2.7.1-slfo.1.1_1.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:20311-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:20311-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2025