SUSE-SU-2026:23894-1: important: Security update for expat

SLE-SECURITY-UPDATES null at suse.de
Tue Sep 29 16:31:39 UTC 2026


# Security update for expat

Announcement ID: SUSE-SU-2026:23894-1  
Release Date: 2026-09-24T07:02:34Z  
Rating: important  
References:

  * bsc#1262263
  * bsc#1264713
  * bsc#1267631
  * bsc#1268572
  * bsc#1268573
  * bsc#1275096
  * bsc#1275594
  * bsc#1275732
  * bsc#1275859
  * bsc#1275860
  * bsc#1275915

  
Cross-References:

  * CVE-2026-41080
  * CVE-2026-45186
  * CVE-2026-50219
  * CVE-2026-56131
  * CVE-2026-56132
  * CVE-2026-56403
  * CVE-2026-56404
  * CVE-2026-56405
  * CVE-2026-56406
  * CVE-2026-56407
  * CVE-2026-56408
  * CVE-2026-56409
  * CVE-2026-56410
  * CVE-2026-56411
  * CVE-2026-56412
  * CVE-2026-66046
  * CVE-2026-72522
  * CVE-2026-76641
  * CVE-2026-76956
  * CVE-2026-76957

  
CVSS scores:

  * CVE-2026-41080 ( SUSE ):  2.0
    CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-41080 ( SUSE ):  2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
  * CVE-2026-41080 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2026-41080 ( NVD ):  2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-45186 ( SUSE ):  2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-45186 ( NVD ):  2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-45186 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-45186 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-50219 ( SUSE ):  4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-50219 ( NVD ):  4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-50219 ( NVD ):  5.9 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-56131 ( SUSE ):  4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-56131 ( NVD ):  4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-56132 ( SUSE ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56132 ( NVD ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56132 ( NVD ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56403 ( SUSE ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56403 ( NVD ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56403 ( NVD ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56404 ( SUSE ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56404 ( NVD ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56404 ( NVD ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56405 ( SUSE ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56405 ( NVD ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56405 ( NVD ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56406 ( SUSE ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56406 ( NVD ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56407 ( SUSE ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56407 ( NVD ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56408 ( SUSE ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56408 ( NVD ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56409 ( SUSE ):  4.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
  * CVE-2026-56409 ( NVD ):  6.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
  * CVE-2026-56410 ( SUSE ):  6.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
  * CVE-2026-56410 ( NVD ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56411 ( SUSE ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56411 ( NVD ):  6.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-56412 ( SUSE ):  4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-56412 ( NVD ):  4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-56412 ( NVD ):  5.9 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-66046 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-66046 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-66046 ( NVD ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-66046 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-72522 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-72522 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-72522 ( NVD ):  6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-76641 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-76641 ( NVD ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-76641 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-76956 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-76956 ( NVD ):  5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-76956 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-76957 ( SUSE ):  4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-76957 ( NVD ):  4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-76957 ( NVD ):  7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

  
Affected Products:

  * SUSE Linux Micro 6.2

  
  
An update that solves 20 vulnerabilities can now be installed.

## Description:

This update for expat fixes the following issues:

  * CVE-2026-41080: crafted XML document can cause a denial of service
    (bsc#1262263).
  * CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of
    attribute name collision checks allows a denial of service via moderately
    sized crafted XML input (bsc#1264713).
  * CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for
    calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or
    XML_ParserReset from within handlers in cases of a policy violation
    (bsc#1267631).
  * CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for
    calls to XML_ResumeParser from within handlers in cases of a policy
    violation (bsc#1268572).
  * CVE-2026-56132: mishandled memory reallocation during array scaffolding in
    doProlog can cause heap-based buffer overflows (bsc#1268573).
  * CVE-2026-56403: integer overflow in the storeAtts function can cause memory
    corruption and potential arbitrary code execution (bsc#1275096).
  * CVE-2026-56404: integer overflow in the addBinding function can cause
    undersized memory allocations, memory corruption, and application crashes
    (bsc#1275096).
  * CVE-2026-56405: integer overflow in the getAttributeId function can cause
    heap memory corruption and arbitrary code execution (bsc#1275096).
  * CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause
    integer overflows, memory corruption, and application crashes (bsc#1275096).
  * CVE-2026-56407: integer overflow in doProlog related to entity text length
    can cause memory corruption and denial of service (bsc#1275096).
  * CVE-2026-56408: integer overflow in the copyString function can cause heap
    memory corruption and application crashes (bsc#1275096).
  * CVE-2026-56409: integer overflow in the xmlwf utility output filename
    handling can allow path buffer corruption and arbitrary file write
    conditions (bsc#1275096).
  * CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility
    can cause memory corruption, information disclosure, and potential code
    execution (bsc#1275096).
  * CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations
    in xmlwf can cause memory corruption and denial of service (bsc#1275096).
  * CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can
    cause use-after-free conditions and arbitrary code execution (bsc#1275096).
  * CVE-2026-66046: libexpat: denial of service vulnerability caused by
    quadratic algorithmic complexity in the storeAtts() function in xmlparse.c
    (bsc#1275732).
  * CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due
    to low surrogates being treated the same as high surrogates during Unicode
    processing (bsc#1275594).
  * CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read
    vulnerability that allows attackers to trigger memory corruption
    (bsc#1275915).
  * CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation
    of getentropy's return code leads to insufficient entropy, which results in
    being vulnerable to hash flooding attacks, causing a denial of service via
    crafted X (bsc#1275860).
  * CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with
    custom encoding callbacks. (bsc#1275859).

Changes for expat:

  * Updated to version 2.8.4

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Micro 6.2  
    zypper in -t patch SUSE-SL-Micro-6.2-1754

## Package List:

  * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64)
    * libexpat1-debuginfo-2.8.4-160000.1.1
    * expat-debugsource-2.8.4-160000.1.1
    * libexpat1-2.8.4-160000.1.1
    * expat-debuginfo-2.8.4-160000.1.1

## References:

  * https://www.suse.com/security/cve/CVE-2026-41080.html
  * https://www.suse.com/security/cve/CVE-2026-45186.html
  * https://www.suse.com/security/cve/CVE-2026-50219.html
  * https://www.suse.com/security/cve/CVE-2026-56131.html
  * https://www.suse.com/security/cve/CVE-2026-56132.html
  * https://www.suse.com/security/cve/CVE-2026-56403.html
  * https://www.suse.com/security/cve/CVE-2026-56404.html
  * https://www.suse.com/security/cve/CVE-2026-56405.html
  * https://www.suse.com/security/cve/CVE-2026-56406.html
  * https://www.suse.com/security/cve/CVE-2026-56407.html
  * https://www.suse.com/security/cve/CVE-2026-56408.html
  * https://www.suse.com/security/cve/CVE-2026-56409.html
  * https://www.suse.com/security/cve/CVE-2026-56410.html
  * https://www.suse.com/security/cve/CVE-2026-56411.html
  * https://www.suse.com/security/cve/CVE-2026-56412.html
  * https://www.suse.com/security/cve/CVE-2026-66046.html
  * https://www.suse.com/security/cve/CVE-2026-72522.html
  * https://www.suse.com/security/cve/CVE-2026-76641.html
  * https://www.suse.com/security/cve/CVE-2026-76956.html
  * https://www.suse.com/security/cve/CVE-2026-76957.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1262263
  * https://bugzilla.suse.com/show_bug.cgi?id=1264713
  * https://bugzilla.suse.com/show_bug.cgi?id=1267631
  * https://bugzilla.suse.com/show_bug.cgi?id=1268572
  * https://bugzilla.suse.com/show_bug.cgi?id=1268573
  * https://bugzilla.suse.com/show_bug.cgi?id=1275096
  * https://bugzilla.suse.com/show_bug.cgi?id=1275594
  * https://bugzilla.suse.com/show_bug.cgi?id=1275732
  * https://bugzilla.suse.com/show_bug.cgi?id=1275859
  * https://bugzilla.suse.com/show_bug.cgi?id=1275860
  * https://bugzilla.suse.com/show_bug.cgi?id=1275915

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260929/b76a64e7/attachment.htm>


More information about the sle-security-updates mailing list