MGASA-2026-0378
Dashboard / Vulnerabilities / MGASA-2026-0378
MGASA-2026-0378
Summary: Updated mingw-expat & expat packages fix security vulnerabilities
Details: Expat Denial of Service via storeAtts() Quadratic Complexity. (CVE-2026-66046) Expat Out-of-Bounds Read via dtdCopy. (CVE-2026-76641) In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content. (CVE-2026-76956) libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. (CVE-2026-76957)
References: https://advisories.mageia.org/MGASA-2026-0378.html, https://bugs.mageia.org/show_bug.cgi?id=36233, https://www.openwall.com/lists/oss-security/2026/08/31/13, https://blog.hartwork.org/posts/expat-2-8-4-released/, https://github.com/libexpat/libexpat/blob/R_2_8_4/expat/Changes, https://nvd.nist.gov/vuln/detail/cve-2026-66046, https://nvd.nist.gov/vuln/detail/cve-2026-76641, https://nvd.nist.gov/vuln/detail/cve-2026-76956, https://nvd.nist.gov/vuln/detail/cve-2026-76957
Affected packages
Package
Name: mingw-expat
Purl: pkg:rpm/mageia/mingw-expat?arch=source&distro=mageia-10
Affected ranges
Type: ECOSYSTEM
Events:
