SUSE-SU-2026:23894-1: important: Security update for expat
SLE-SECURITY-UPDATES
null at suse.de
Tue Sep 29 16:31:39 UTC 2026
# Security update for expat
Announcement ID: SUSE-SU-2026:23894-1
Release Date: 2026-09-24T07:02:34Z
Rating: important
References:
* bsc#1262263
* bsc#1264713
* bsc#1267631
* bsc#1268572
* bsc#1268573
* bsc#1275096
* bsc#1275594
* bsc#1275732
* bsc#1275859
* bsc#1275860
* bsc#1275915
Cross-References:
* CVE-2026-41080
* CVE-2026-45186
* CVE-2026-50219
* CVE-2026-56131
* CVE-2026-56132
* CVE-2026-56403
* CVE-2026-56404
* CVE-2026-56405
* CVE-2026-56406
* CVE-2026-56407
* CVE-2026-56408
* CVE-2026-56409
* CVE-2026-56410
* CVE-2026-56411
* CVE-2026-56412
* CVE-2026-66046
* CVE-2026-72522
* CVE-2026-76641
* CVE-2026-76956
* CVE-2026-76957
CVSS scores:
* CVE-2026-41080 ( SUSE ): 2.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-41080 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-41080 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-41080 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-45186 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-45186 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-45186 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-45186 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-50219 ( SUSE ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-50219 ( NVD ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-50219 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-56131 ( SUSE ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-56131 ( NVD ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-56132 ( SUSE ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56132 ( NVD ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56132 ( NVD ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56403 ( SUSE ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56403 ( NVD ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56403 ( NVD ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56404 ( SUSE ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56404 ( NVD ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56404 ( NVD ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56405 ( SUSE ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56405 ( NVD ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56405 ( NVD ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56406 ( SUSE ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56406 ( NVD ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56407 ( SUSE ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56407 ( NVD ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56408 ( SUSE ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56408 ( NVD ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56409 ( SUSE ): 4.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
* CVE-2026-56409 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
* CVE-2026-56410 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
* CVE-2026-56410 ( NVD ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56411 ( SUSE ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56411 ( NVD ): 6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-56412 ( SUSE ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-56412 ( NVD ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-56412 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-66046 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-66046 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-66046 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-66046 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-72522 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-72522 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-72522 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-76641 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-76641 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-76641 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-76956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-76956 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-76956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-76957 ( SUSE ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-76957 ( NVD ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-76957 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* SUSE Linux Micro 6.2
An update that solves 20 vulnerabilities can now be installed.
## Description:
This update for expat fixes the following issues:
* CVE-2026-41080: crafted XML document can cause a denial of service
(bsc#1262263).
* CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of
attribute name collision checks allows a denial of service via moderately
sized crafted XML input (bsc#1264713).
* CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for
calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or
XML_ParserReset from within handlers in cases of a policy violation
(bsc#1267631).
* CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for
calls to XML_ResumeParser from within handlers in cases of a policy
violation (bsc#1268572).
* CVE-2026-56132: mishandled memory reallocation during array scaffolding in
doProlog can cause heap-based buffer overflows (bsc#1268573).
* CVE-2026-56403: integer overflow in the storeAtts function can cause memory
corruption and potential arbitrary code execution (bsc#1275096).
* CVE-2026-56404: integer overflow in the addBinding function can cause
undersized memory allocations, memory corruption, and application crashes
(bsc#1275096).
* CVE-2026-56405: integer overflow in the getAttributeId function can cause
heap memory corruption and arbitrary code execution (bsc#1275096).
* CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause
integer overflows, memory corruption, and application crashes (bsc#1275096).
* CVE-2026-56407: integer overflow in doProlog related to entity text length
can cause memory corruption and denial of service (bsc#1275096).
* CVE-2026-56408: integer overflow in the copyString function can cause heap
memory corruption and application crashes (bsc#1275096).
* CVE-2026-56409: integer overflow in the xmlwf utility output filename
handling can allow path buffer corruption and arbitrary file write
conditions (bsc#1275096).
* CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility
can cause memory corruption, information disclosure, and potential code
execution (bsc#1275096).
* CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations
in xmlwf can cause memory corruption and denial of service (bsc#1275096).
* CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can
cause use-after-free conditions and arbitrary code execution (bsc#1275096).
* CVE-2026-66046: libexpat: denial of service vulnerability caused by
quadratic algorithmic complexity in the storeAtts() function in xmlparse.c
(bsc#1275732).
* CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due
to low surrogates being treated the same as high surrogates during Unicode
processing (bsc#1275594).
* CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read
vulnerability that allows attackers to trigger memory corruption
(bsc#1275915).
* CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation
of getentropy's return code leads to insufficient entropy, which results in
being vulnerable to hash flooding attacks, causing a denial of service via
crafted X (bsc#1275860).
* CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with
custom encoding callbacks. (bsc#1275859).
Changes for expat:
* Updated to version 2.8.4
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Micro 6.2
zypper in -t patch SUSE-SL-Micro-6.2-1754
## Package List:
* SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64)
* libexpat1-debuginfo-2.8.4-160000.1.1
* expat-debugsource-2.8.4-160000.1.1
* libexpat1-2.8.4-160000.1.1
* expat-debuginfo-2.8.4-160000.1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-41080.html
* https://www.suse.com/security/cve/CVE-2026-45186.html
* https://www.suse.com/security/cve/CVE-2026-50219.html
* https://www.suse.com/security/cve/CVE-2026-56131.html
* https://www.suse.com/security/cve/CVE-2026-56132.html
* https://www.suse.com/security/cve/CVE-2026-56403.html
* https://www.suse.com/security/cve/CVE-2026-56404.html
* https://www.suse.com/security/cve/CVE-2026-56405.html
* https://www.suse.com/security/cve/CVE-2026-56406.html
* https://www.suse.com/security/cve/CVE-2026-56407.html
* https://www.suse.com/security/cve/CVE-2026-56408.html
* https://www.suse.com/security/cve/CVE-2026-56409.html
* https://www.suse.com/security/cve/CVE-2026-56410.html
* https://www.suse.com/security/cve/CVE-2026-56411.html
* https://www.suse.com/security/cve/CVE-2026-56412.html
* https://www.suse.com/security/cve/CVE-2026-66046.html
* https://www.suse.com/security/cve/CVE-2026-72522.html
* https://www.suse.com/security/cve/CVE-2026-76641.html
* https://www.suse.com/security/cve/CVE-2026-76956.html
* https://www.suse.com/security/cve/CVE-2026-76957.html
* https://bugzilla.suse.com/show_bug.cgi?id=1262263
* https://bugzilla.suse.com/show_bug.cgi?id=1264713
* https://bugzilla.suse.com/show_bug.cgi?id=1267631
* https://bugzilla.suse.com/show_bug.cgi?id=1268572
* https://bugzilla.suse.com/show_bug.cgi?id=1268573
* https://bugzilla.suse.com/show_bug.cgi?id=1275096
* https://bugzilla.suse.com/show_bug.cgi?id=1275594
* https://bugzilla.suse.com/show_bug.cgi?id=1275732
* https://bugzilla.suse.com/show_bug.cgi?id=1275859
* https://bugzilla.suse.com/show_bug.cgi?id=1275860
* https://bugzilla.suse.com/show_bug.cgi?id=1275915
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260929/b76a64e7/attachment.htm>
More information about the sle-security-updates
mailing list