Debian Patches

Status for expat/2.5.0-1+deb12u4

Patch Description Author Forwarded Bugs Origin Last update
fix-expat-noconfig.patch libexpat.so.X.Y.Z is installed in /lib/${DEB_HOST_MULTIARCH}

instead of /usr/lib/${DEB_HOST_MULTIARCH}, thus the path of the shared library
is not relative to the location of this cmake file (Closes: #995907)
Andrius Merkys <merkys@debian.org> not-needed 2026-08-30
fix-expat-cmake.patch fix-expat-cmake "Laszlo Boszormenyi (GCS)" <gcs@debian.org> no 2026-08-30
CVE-2024-45490.patch [PATCH 1/3] lib: Reject negative len for XML_ParseBuffer
Reported by TaiYou
Sebastian Pipping <sebastian@pipping.org> no 2024-08-19
CVE-2024-45491.patch lib: Detect integer overflow in dtdCopy
Reported by TaiYou
Sebastian Pipping <sebastian@pipping.org> no 2024-08-19
CVE-2024-45492.patch lib: Detect integer overflow in function nextScaffoldPart
Reported by TaiYou
Sebastian Pipping <sebastian@pipping.org> no 2024-08-19
expat-2.5.0-CVE-2023-52425.patch expat-2.5.0-CVE-2023-52425
commit 678a2f7efcaaa977886e055613f2332615aef82c

Fix CVE-2023-52425
Tomas Korbar <tkorbar@redhat.com> no 2024-02-13
expat-2.5.0-CVE-2024-50602.patch expat-2.5.0-CVE-2024-50602
commit 38905b99bb78a6a691ed8358f30030116783656c

Fix CVE-2024-50602

See https://github.com/libexpat/libexpat/pull/915
Tomas Korbar <tkorbar@redhat.com> no 2024-11-07
expat-2.5.0-CVE-2024-8176.patch expat-2.5.0-CVE-2024-8176
commit c0de4903900004dd3ca91f246e5f6489a49a132b

Fix CVE-2024-8176
Tomas Korbar <tkorbar@redhat.com> no 2025-03-24
CVE-2026-50219-1.patch lib: Introduce handler call depth tracking Sebastian Pipping <sebastian@pipping.org> no backport, https://github.com/libexpat/libexpat/pull/1246/commits 2026-05-26
CVE-2026-50219-2.patch lib: Prepare m_notStandaloneHandler, m_externalEntityRefHandler, m_unknownEncodingHandler calls for upcoming wrapping Sebastian Pipping <sebastian@pipping.org> no backport, https://github.com/libexpat/libexpat/pull/1246/commits 2026-05-26
CVE-2025-59375-8.patch lib: Make XML_MemFree and XML_FreeContentModel match their siblings
.. XML_MemMalloc and XML_MemRealloc in structure, prior to upcoming changes
Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/1270e5bc0836d296ac4970fc9e1cf53d83972083 2025-09-07
CVE-2025-59375-9.patch lib: Add XML_GE to XML_GetFeatureList and XML_FeatureEnum Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/8a6c61de4a425977e357cafd8667a0d7771ce292 2023-10-26
CVE-2025-59375-10.patch lib: Implement tracking of dynamic memory allocations
**PLEASE NOTE** that distributors intending to backport (or cherry-pick)
this fix need to copy 99% of the related pull request, not just this
commit, to not end up with a state that literally does both too much and
too little at the same time. Appending ".diff" to the pull request URL
could be of help.
Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/cfce28e171676fe6f70d17b97ed8a59eaeb83f15 2025-09-01
CVE-2025-59375-11.patch lib: Exclude the content model from allocation tracking
.. so that applications that are not using XML_FreeContentModel
but plain free(..) or .free_fcn() to free the content model's
memory are safe
Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/7e35240dc97e9fd4f609e31f27c27b659535e436 2025-09-11
CVE-2025-59375-12.patch lib: Exclude the main input buffer from allocation tracking
.. so that control of the input buffer size remains with the
application using Expat
Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/ae4086198d710a62a0a1560007b81307dba72909 2025-09-09
CVE-2025-59375-13.patch lib: Exclude XML_Mem* functions from allocation tracking
.. so that allocations by the user application
are not being limited.
Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/96c7467281c72028aada525c1d3822512758b266 2025-09-07
CVE-2025-59375-14.patch xmlwf: Wire allocation tracker config to existing arguments -a and -b Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/78366891a586f293aeff60a14a55e4afe1169586 2025-09-02
CVE-2025-59375-15.patch lib: Fix alignment of internal allocations for some non-amd64 architectures

sparc32 is known to be affected.
Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/4b43b8dacc96fd538254e17a69abc9745c3a2ed4 2025-09-19
CVE-2026-24515.patch lib: Make XML_ExternalEntityParserCreate copy unknown encoding handler user data

Patch suggested by Artiphishell Inc.
Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/86fc914a7acc49246d5fde0ab6ed97eb8a0f15f9 2026-01-18
CVE-2026-25210-1.patch lib: Make a doubling more readable Matthew Fernandez <matthew.fernandez@gmail.com> no upstream, https://github.com/libexpat/libexpat/commit/7ddea353ad3795f7222441274d4d9a155b523cba 2025-10-02
CVE-2026-25210-2.patch lib: Realign a size with the `REALLOC` type signature it is passed into

Note that this implicitly assumes `tag->bufEnd >= tag->buf`, which should
already be guaranteed true.
Matthew Fernandez <matthew.fernandez@gmail.com> no upstream, https://github.com/libexpat/libexpat/commit/8855346359a475c022ec8c28484a76c852f144d9 2025-10-02
CVE-2026-25210-3.patch lib: Introduce an integer overflow check for tag buffer reallocation Matthew Fernandez <matthew.fernandez@gmail.com> no upstream, https://github.com/libexpat/libexpat/commit/9c2d990389e6abe2e44527eeaa8b39f16fe859c7 2025-10-02
CVE-2024-28757.patch lib/xmlparse.c: Detect billion laughs attack with isolated external parser

When parsing DTD content with code like ..

XML_Parser parser = XML_ParserCreate(NULL);
XML_Parser ext_parser = XML_ExternalEntityParserCreate(parser, NULL, NULL);
enum XML_Status status = XML_Parse(ext_parser, doc, (int)strlen(doc), XML_TRUE);

.. there are 0 bytes accounted as direct input and all input from `doc` accounted
as indirect input. Now function accountingGetCurrentAmplification cannot calculate
the current amplification ratio as "(direct + indirect) / direct", and it did refuse
to divide by 0 as one would expect, but it returned 1.0 for this case to indicate
no amplification over direct input. As a result, billion laughs attacks from
DTD-only input were not detected with this isolated way of using an external parser.

The new approach is to assume direct input of length not 0 but 22 -- derived from
ghost input "<!ENTITY a SYSTEM 'b'>", the shortest possible way to include an external
DTD --, and do the usual "(direct + indirect) / direct" math with "direct := 22".

GitHub issue #839 has more details on this issue and its origin in ClusterFuzz
finding 66812.
Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/1d50b80cf31de87750103656f6eb693746854aa8 2024-03-04
CVE-2026-32776.patch Fix NULL function-pointer dereference for empty external parameter entities

When an external parameter entity with empty text is referenced inside
an entity declaration value, the sub-parser created to handle it receives
0 bytes of input. Processing enters entityValueInitProcessor which calls
storeEntityValue() with the parser's encoding; since no bytes were ever
processed, encoding detection has not yet occurred and the encoding is
still the initial probing encoding set up by XmlInitEncoding(). That
encoding only populates scanners[] (for prolog and content), not
literalScanners[]. XmlEntityValueTok() calls through
literalScanners[XML_ENTITY_VALUE_LITERAL] which is NULL, causing a
SEGV.

Skip the tokenization loop entirely when entityTextPtr >= entityTextEnd,
and initialize the `next` pointer before the early exit so that callers
(callStoreEntityValue) receive a valid value through nextPtr.
Francesco Bertolaccini <francesco.bertolaccini@trailofbits.com> no upstream, https://github.com/libexpat/libexpat/commit/5be25657583ea91b09025c858b4785834c20f59c 2026-03-03
CVE-2026-32777.patch lib: Reject XML_TOK_INSTANCE_START infinite loop in entityValueProcessor

.. that OSS-Fuzz/ClusterFuzz uncovered
Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/55cda8c7125986e17d7e1825cba413bd94a35d02 2026-03-01
CVE-2026-32778.patch copy prefix name to pool before lookup
.. so that we cannot end up with a zombie PREFIX in the pool
that has NULL for a name.
laserbear <10689391+Laserbear@users.noreply.github.com> no upstream, https://github.com/libexpat/libexpat/commit/576b61e42feeea704253cb7c7bedb2eeb3754387 2026-03-08
CVE-2026-45186-1.patch lib: Extract a constant for upcoming reuse Sebastian Pipping <sebastian@pipping.org> no backport, https://github.com/libexpat/libexpat/pull/1216/commits/fb35f2d2040d114f355bae8a7450942533237530 2026-03-08
CVE-2026-45186-2.patch lib: Introduce ELEMENT_TYPE.defaultAttsNames Sebastian Pipping <sebastian@pipping.org> no backport, https://github.com/libexpat/libexpat/pull/1216/commits/7f0f1b9e70d937072d2e9e37ae9edf27784cc080 2026-03-08
CVE-2026-45186-3.patch lib: Leverage ELEMENT_TYPE.defaultAttsNames for attribute collision detection

.. to resolve quadratic runtime behavior
Sebastian Pipping <sebastian@pipping.org> no backport, https://github.com/libexpat/libexpat/pull/1216/commits/4cd4eb0683e04cd45a2ffc81a08ca2a2663994b5 2026-03-08
CVE-2026-45186-4.patch lib: Remove unnecessary `lookup` casts Matthew Fernandez <matthew.fernandez@gmail.com> no backport, https://github.com/libexpat/libexpat/pull/1216/commits/57ccdbfd395d1785a6c1ad75901f9534aa1fdc56 2026-05-15
CVE-2026-66046-1.patch lib: Rename hash table `defaultAttsNames` to `defaultAttForName`
It was previously used as a "set". This prepares for the upcoming
change to a true "dictionary".
Sebastian Pipping <sebastian@pipping.org> no backport, https://github.com/libexpat/libexpat/commit/98f5acc146af76859cd7c345c0906e9e9e8ea656 2026-08-13
CVE-2026-66046-2.patch lib: Migrate .isCdata lookup from a linear loop to a hash table lookup

.. to resolve quadratic runtime
Sebastian Pipping <sebastian@pipping.org> no backport, https://github.com/libexpat/libexpat/commit/f8f7c4ffd883e3c2c58f0ebb49416a6c1d248738 2026-08-13
CVE-2026-56406-2.patch lib: Make internal `m_position` use `uint64_t` to support >4 GiB documents Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/pull/1300 2026-08-06
CVE-2026-56406-3.patch lib: Make internal `m_parseEndByteIndex` use `uint64_t` to support >2 GiB documents

Fixes a regression from Expat 2.8.2.
Evgeny Kotkov <kotkov@apache.org> no upstream, https://github.com/libexpat/libexpat/pull/1300 2026-08-06
CVE-2026-56407.patch cap entity textLen against signed integer overflow netliomax25-code <netliomax25@gmail.com> no upstream, https://github.com/libexpat/libexpat/commit/30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13 2026-06-02
CVE-2026-56408.patch lib: Waterproof `copyString` from integer overflow Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/16e2efd867ea8567ffa012210b52ef5918e20817 2026-04-23
CVE-2026-56409.patch xmlwf: protect output path join from integer overflow netliomax25-code <netliomax25@gmail.com> no backport, https://github.com/libexpat/libexpat/commit/61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e 2026-06-01
CVE-2026-56410-1.patch xmlwf: protect resolveSystemId from integer overflow netliomax25-code <netliomax25@gmail.com> no backport, https://github.com/libexpat/libexpat/commit/deeb97f7c88d17a16b0ea2521a13733abc283347 2026-05-29
CVE-2026-56410-2.patch xmlwf: guard each operator in resolveSystemId length sum netliomax25-code <netliomax25@gmail.com> no upstream, https://github.com/libexpat/libexpat/commit/cee20e91bf14dc7f6d2fc48f0d70d86b2dc3afea 2026-05-30
CVE-2026-56411-0.patch Free data->currentDoctypeName if notations is NULL
We leak it and don't change it.
AZero13 <gfunni234@gmail.com> no upstream, https://github.com/libexpat/libexpat/commit/2c90a96917f9b0222ef5955adf6f3ee504ad00b9 2025-12-28
CVE-2026-56411-1.patch xmlwf: protect notation list allocation from integer overflow netliomax25-code <netliomax25@gmail.com> no upstream, https://github.com/libexpat/libexpat/commit/528a4e5017e1bd3b48b689fd0c131df940ae3ea5 2026-06-02
CVE-2026-56412.patch lib: guard XML_TOK_DATA_CHARS handler calls in doCdataSection() hextheshadow <hextheshadow0x@gmail.com> no upstream, https://github.com/libexpat/libexpat/commit/d19e834794060d18c061d94452c35d725393ea58 2026-06-20
CVE-2026-76957.patch Protect custom encoding callbacks from parser reentry Darren Carreras <carrerasdarren@gmail.com> no upstream, https://github.com/libexpat/libexpat/pull/1322 2026-08-17
CVE-2026-72522.patch Merge pull request #1296 from libexpat/mozilla-2053153
[CVE-2026-72522] Fix an OOB read and the resulting infinite loop in `*_toUtf16` functions
Sebastian Pipping <sebastian@pipping.org> no backport, https://github.com/libexpat/libexpat/commit/27c6536c2bfa857b6678b1038d14f43fd65a4aa6 2026-08-10
CVE-2025-59375-1.patch lib: Make function dtdCreate use macro MALLOC
.. and give its body access to the parser for upcoming changes
Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/0872c189db6e457084fca335662a9cb49e8ec4c7 2025-09-01
CVE-2025-59375-2.patch lib: Make string pools use macros MALLOC, FREE, REALLOC Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/8768dadae479d9f2e984b747fb2ba79bb78de94f 2025-09-01
CVE-2025-59375-3.patch lib: Make function hash tables use macros MALLOC and FREE Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/4fc6f1ee9f2b282cfe446bf645c992e37f8c3e15 2025-09-01
CVE-2025-59375-4.patch lib: Make function copyString use macro MALLOC Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/51487ad9d760faa4809b0f8e189d2f666317e41a 2025-09-01
CVE-2025-59375-5.patch lib: Make function dtdCopy use macro MALLOC Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/4e7a5d03daf672f20c73d40dc8970385c18b30d3 2025-09-01
CVE-2025-59375-6.patch lib: Make function dtdDestroy use macro FREE Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/53a3eda0ae2e0317afd071b72b41976053d82732 2025-09-01
CVE-2025-59375-7.patch lib: Make function dtdReset use macro FREE Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/b3f0bda5f5e979781469532f7c304f7e223568d5 2025-09-01
CVE-2026-50219-3.patch lib: Register m_*Handler with handler call depth tracking
- m_attlistDeclHandler
- m_characterDataHandler
- m_commentHandler
- m_defaultHandler
- m_elementDeclHandler
- m_endCdataSectionHandler
- m_endDoctypeDeclHandler
- m_endElementHandler
- m_endNamespaceDeclHandler
- m_entityDeclHandler
- m_externalEntityRefHandler
- m_notationDeclHandler
- m_notStandaloneHandler
- m_processingInstructionHandler
- m_skippedEntityHandler
- m_startCdataSectionHandler
- m_startDoctypeDeclHandler
- m_startElementHandler
- m_startNamespaceDeclHandler
- m_unknownEncodingHandler
- m_unparsedEntityDeclHandler
- m_xmlDeclHandler
Sebastian Pipping <sebastian@pipping.org> no backport, https://github.com/libexpat/libexpat/pull/1246/commits 2026-05-26
CVE-2026-50219-4.patch lib: Protect XML_* from being called from a handler
- XML_GetBuffer
- XML_Parse
- XML_ParseBuffer
- XML_ParserFree
- XML_ParserReset
Sebastian Pipping <sebastian@pipping.org> no backport, https://github.com/libexpat/libexpat/pull/1246/commits 2026-05-26
CVE-2026-56131.patch lib: protect XML_ResumeParser from being called from a handler
The handler-reentrancy guards from CVE-2026-50219 cover XML_Parse, XML_ParseBuffer, XML_GetBuffer, XML_ParserFree and XML_ParserReset but not XML_ResumeParser, which drives the parser through callProcessor in the same way.
netliomax25-code <netliomax25@gmail.com> no backport, https://github.com/libexpat/libexpat/pull/1267/commits 2026-06-06
CVE-2026-56403-0.patch lib: split inessential reuse of `n` in `storeAtts`
This change is intended to reduce the diff of an upcoming commit.
Matthew Fernandez <matthew.fernandez@gmail.com> no backport, https://github.com/libexpat/libexpat/commit/99256f5fc2885e2176c9c9dd14af8625deab02f2 2026-05-19
CVE-2026-56403-1.patch lib: Protect function `storeAtts` from signed integer overflow Sebastian Pipping <sebastian@pipping.org> no backport, https://github.com/libexpat/libexpat/commit/12dc6d8d3d65f79471a94d8565f6bf1cf245f648 2026-05-20
CVE-2026-56403-2.patch xmlwf: Protect function `xcsdup` from signed integer overflow Sebastian Pipping <sebastian@pipping.org> no backport, https://github.com/libexpat/libexpat/commit/147c8f36d6277d5c6011c098370a8362aed47b15 2026-05-22
CVE-2026-56404.patch lib: protect function addBinding from signed integer overflow netliomax25-code <netliomax25@gmail.com> no upstream, https://github.com/libexpat/libexpat/commit/babfc48090977cbf7be24b2c48f6053dca75c164 2026-05-28
CVE-2026-56405.patch lib: Protect function getAttributeId from signed integer overflow netliomax25-code <netliomax25@gmail.com> no upstream, https://github.com/libexpat/libexpat/commit/2c6c42d33689f6b266a5267b639e03cde17e53c0 2026-05-29
CVE-2026-56406-1.patch lib: Copy overflow check from `XML_Parse` to `XML_ParseBuffer` Sebastian Pipping <sebastian@pipping.org> no upstream, https://github.com/libexpat/libexpat/commit/99d8454fdf900a6d00c2a52748e6c0eeb507574d 2026-05-31
CVE-2026-66046-3.patch lib: Fix out-of-bounds read from hash table entries created by dtdCopy

Commit f8f7c4ff grew the entries of ELEMENT_TYPE member
.defaultAttForName from structure NAMED to the larger structure
NAME_AND_DEFAULT_ATTRIBUTE and adjusted function defineAttribute
accordingly, but function dtdCopy kept creating entries of size
sizeof(NAMED). Because function lookup allocates exactly createSize
bytes, function storeAtts reads member .attIndex past the end of those
entries whenever attributes are parsed by a parser that was created by
XML_ExternalEntityParserCreate.

That out-of-bounds value is then used as an index into member
.defaultAtts, so the effects range from silently not normalizing
whitespace in attributes that are not of type CDATA, to dereferencing a
wild pointer: a release build of master segfaults in function storeAtts
on the document used by the new test. A zero-filled heap happens to
yield index 0, which is why the existing tests did not catch this.

Member .attIndex is now stored the way function defineAttribute stores
it, i.e. keeping the index of the first declaration, so that a copied
DTD resolves attributes exactly like the DTD that it was copied from.

This was found while backporting the fix for CVE-2026-66046 onto Expat
2.6.4 for the OpenCloudOS Stream distribution. Only master is affected,
no released version of Expat contains commit f8f7c4ff.
Zeyou Liu <zeyouliu@tencent.com> no backport, https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf 2026-08-20
CVE-2026-93990.patch lib: reject UTF-16 high surrogate not followed by a low surrogate Kartik Kenchi <netliomax25@gmail.com> no upstream, https://github.com/libexpat/libexpat/commit/0cfd15bdf4b2c22d6b0df73610709dfb60921091 2026-06-23

All known versions for source package 'expat'

Links