Re: [LFS Trac] #5933: expat-2.8.1 (Security update)

"LFS Trac" ([email protected] via lfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.book
Message-ID <[email protected]>
#5933: expat-2.8.1 (Security update)
-------------------------+-----------------------
 Reporter:  Bruce Dubbs  |       Owner:  lfs-book
     Type:  enhancement  |      Status:  new
 Priority:  high         |   Milestone:  13.1
Component:  Book         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-----------------------
Comment (by Douglas R. Reno):

 An update from the maintainer on oss-security:

 {{{
 Hello oss-security,


 just a quick note that libexpat 2.8.1 (or "Expat 2.8.1") released
 yesterday is fixing CVE-2026-45186:

   Fix quadratic runtime from attribute name collision checks that
   allowed denial of service attacks through moderately sized crafted
   XML input (CWE-407).
   Please note that a layer of compression around XML can significantly
   reduce the minimum attack payload size.

 Some key links are:

 - The blog post about it
   https://blog.hartwork.org/posts/expat-2-8-1-released/

 - The change log of release 2.8.1
   https://github.com/libexpat/libexpat/blob/R_2_8_1/expat/Changes

 - The fixing pull request
   https://github.com/libexpat/libexpat/pull/1216

 - The NVD CVE metadata
   https://nvd.nist.gov/vuln/detail/CVE-2026-45186

 PS: The CVE database lists an unrealistically low CVSS score for this.
     The complexity of an attack is very low (not "High") and the attack
     vector is remote (not "Local"). I have asked Mitre to fix this
     earlier today. My blog post linked above has a few more words on
     that topic.

 Best

 Sebastian
 }}}
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5933#comment:2>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.

-- 
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.