MGASA-2026-0378

Source
https://advisories.mageia.org/MGASA-2026-0378.html
Import Source
https://advisories.mageia.org/MGASA-2026-0378.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0378
Upstream
Published
2026-09-05T04:35:57Z
Modified
2026-09-05T04:45:03Z
Summary
Updated mingw-expat & expat packages fix security vulnerabilities
Details

Expat Denial of Service via storeAtts() Quadratic Complexity. (CVE-2026-66046) Expat Out-of-Bounds Read via dtdCopy. (CVE-2026-76641) In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content. (CVE-2026-76956) libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. (CVE-2026-76957)

References
Credits

Affected packages

Mageia:10 / mingw-expat

Package

Name
mingw-expat
Purl
pkg:rpm/mageia/mingw-expat?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.8.4-1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0378.json"

Mageia:10 / expat

Package

Name
expat
Purl
pkg:rpm/mageia/expat?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.8.4-1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0378.json"