Debian Patches
Status for expat/2.5.0-1+deb12u4
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| fix-expat-noconfig.patch | libexpat.so.X.Y.Z is installed in /lib/${DEB_HOST_MULTIARCH} instead of /usr/lib/${DEB_HOST_MULTIARCH}, thus the path of the shared library is not relative to the location of this cmake file (Closes: #995907) |
Andrius Merkys <merkys@debian.org> | not-needed | 2026-08-30 | ||
| fix-expat-cmake.patch | fix-expat-cmake | "Laszlo Boszormenyi (GCS)" <gcs@debian.org> | no | 2026-08-30 | ||
| CVE-2024-45490.patch | [PATCH 1/3] lib: Reject negative len for XML_ParseBuffer Reported by TaiYou |
Sebastian Pipping <sebastian@pipping.org> | no | 2024-08-19 | ||
| CVE-2024-45491.patch | lib: Detect integer overflow in dtdCopy Reported by TaiYou |
Sebastian Pipping <sebastian@pipping.org> | no | 2024-08-19 | ||
| CVE-2024-45492.patch | lib: Detect integer overflow in function nextScaffoldPart Reported by TaiYou |
Sebastian Pipping <sebastian@pipping.org> | no | 2024-08-19 | ||
| expat-2.5.0-CVE-2023-52425.patch | expat-2.5.0-CVE-2023-52425 commit 678a2f7efcaaa977886e055613f2332615aef82c Fix CVE-2023-52425 |
Tomas Korbar <tkorbar@redhat.com> | no | 2024-02-13 | ||
| expat-2.5.0-CVE-2024-50602.patch | expat-2.5.0-CVE-2024-50602 commit 38905b99bb78a6a691ed8358f30030116783656c Fix CVE-2024-50602 See https://github.com/libexpat/libexpat/pull/915 |
Tomas Korbar <tkorbar@redhat.com> | no | 2024-11-07 | ||
| expat-2.5.0-CVE-2024-8176.patch | expat-2.5.0-CVE-2024-8176 commit c0de4903900004dd3ca91f246e5f6489a49a132b Fix CVE-2024-8176 |
Tomas Korbar <tkorbar@redhat.com> | no | 2025-03-24 | ||
| CVE-2026-50219-1.patch | lib: Introduce handler call depth tracking | Sebastian Pipping <sebastian@pipping.org> | no | backport, https://github.com/libexpat/libexpat/pull/1246/commits | 2026-05-26 | |
| CVE-2026-50219-2.patch | lib: Prepare m_notStandaloneHandler, m_externalEntityRefHandler, m_unknownEncodingHandler calls for upcoming wrapping | Sebastian Pipping <sebastian@pipping.org> | no | backport, https://github.com/libexpat/libexpat/pull/1246/commits | 2026-05-26 | |
| CVE-2025-59375-8.patch | lib: Make XML_MemFree and XML_FreeContentModel match their siblings .. XML_MemMalloc and XML_MemRealloc in structure, prior to upcoming changes |
Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/1270e5bc0836d296ac4970fc9e1cf53d83972083 | 2025-09-07 | |
| CVE-2025-59375-9.patch | lib: Add XML_GE to XML_GetFeatureList and XML_FeatureEnum | Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/8a6c61de4a425977e357cafd8667a0d7771ce292 | 2023-10-26 | |
| CVE-2025-59375-10.patch | lib: Implement tracking of dynamic memory allocations **PLEASE NOTE** that distributors intending to backport (or cherry-pick) this fix need to copy 99% of the related pull request, not just this commit, to not end up with a state that literally does both too much and too little at the same time. Appending ".diff" to the pull request URL could be of help. |
Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/cfce28e171676fe6f70d17b97ed8a59eaeb83f15 | 2025-09-01 | |
| CVE-2025-59375-11.patch | lib: Exclude the content model from allocation tracking .. so that applications that are not using XML_FreeContentModel but plain free(..) or .free_fcn() to free the content model's memory are safe |
Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/7e35240dc97e9fd4f609e31f27c27b659535e436 | 2025-09-11 | |
| CVE-2025-59375-12.patch | lib: Exclude the main input buffer from allocation tracking .. so that control of the input buffer size remains with the application using Expat |
Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/ae4086198d710a62a0a1560007b81307dba72909 | 2025-09-09 | |
| CVE-2025-59375-13.patch | lib: Exclude XML_Mem* functions from allocation tracking .. so that allocations by the user application are not being limited. |
Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/96c7467281c72028aada525c1d3822512758b266 | 2025-09-07 | |
| CVE-2025-59375-14.patch | xmlwf: Wire allocation tracker config to existing arguments -a and -b | Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/78366891a586f293aeff60a14a55e4afe1169586 | 2025-09-02 | |
| CVE-2025-59375-15.patch | lib: Fix alignment of internal allocations for some non-amd64 architectures sparc32 is known to be affected. |
Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/4b43b8dacc96fd538254e17a69abc9745c3a2ed4 | 2025-09-19 | |
| CVE-2026-24515.patch | lib: Make XML_ExternalEntityParserCreate copy unknown encoding handler user data Patch suggested by Artiphishell Inc. |
Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/86fc914a7acc49246d5fde0ab6ed97eb8a0f15f9 | 2026-01-18 | |
| CVE-2026-25210-1.patch | lib: Make a doubling more readable | Matthew Fernandez <matthew.fernandez@gmail.com> | no | upstream, https://github.com/libexpat/libexpat/commit/7ddea353ad3795f7222441274d4d9a155b523cba | 2025-10-02 | |
| CVE-2026-25210-2.patch | lib: Realign a size with the `REALLOC` type signature it is passed into Note that this implicitly assumes `tag->bufEnd >= tag->buf`, which should already be guaranteed true. |
Matthew Fernandez <matthew.fernandez@gmail.com> | no | upstream, https://github.com/libexpat/libexpat/commit/8855346359a475c022ec8c28484a76c852f144d9 | 2025-10-02 | |
| CVE-2026-25210-3.patch | lib: Introduce an integer overflow check for tag buffer reallocation | Matthew Fernandez <matthew.fernandez@gmail.com> | no | upstream, https://github.com/libexpat/libexpat/commit/9c2d990389e6abe2e44527eeaa8b39f16fe859c7 | 2025-10-02 | |
| CVE-2024-28757.patch | lib/xmlparse.c: Detect billion laughs attack with isolated external parser When parsing DTD content with code like .. XML_Parser parser = XML_ParserCreate(NULL); XML_Parser ext_parser = XML_ExternalEntityParserCreate(parser, NULL, NULL); enum XML_Status status = XML_Parse(ext_parser, doc, (int)strlen(doc), XML_TRUE); .. there are 0 bytes accounted as direct input and all input from `doc` accounted as indirect input. Now function accountingGetCurrentAmplification cannot calculate the current amplification ratio as "(direct + indirect) / direct", and it did refuse to divide by 0 as one would expect, but it returned 1.0 for this case to indicate no amplification over direct input. As a result, billion laughs attacks from DTD-only input were not detected with this isolated way of using an external parser. The new approach is to assume direct input of length not 0 but 22 -- derived from ghost input "<!ENTITY a SYSTEM 'b'>", the shortest possible way to include an external DTD --, and do the usual "(direct + indirect) / direct" math with "direct := 22". GitHub issue #839 has more details on this issue and its origin in ClusterFuzz finding 66812. |
Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/1d50b80cf31de87750103656f6eb693746854aa8 | 2024-03-04 | |
| CVE-2026-32776.patch | Fix NULL function-pointer dereference for empty external parameter entities When an external parameter entity with empty text is referenced inside an entity declaration value, the sub-parser created to handle it receives 0 bytes of input. Processing enters entityValueInitProcessor which calls storeEntityValue() with the parser's encoding; since no bytes were ever processed, encoding detection has not yet occurred and the encoding is still the initial probing encoding set up by XmlInitEncoding(). That encoding only populates scanners[] (for prolog and content), not literalScanners[]. XmlEntityValueTok() calls through literalScanners[XML_ENTITY_VALUE_LITERAL] which is NULL, causing a SEGV. Skip the tokenization loop entirely when entityTextPtr >= entityTextEnd, and initialize the `next` pointer before the early exit so that callers (callStoreEntityValue) receive a valid value through nextPtr. |
Francesco Bertolaccini <francesco.bertolaccini@trailofbits.com> | no | upstream, https://github.com/libexpat/libexpat/commit/5be25657583ea91b09025c858b4785834c20f59c | 2026-03-03 | |
| CVE-2026-32777.patch | lib: Reject XML_TOK_INSTANCE_START infinite loop in entityValueProcessor .. that OSS-Fuzz/ClusterFuzz uncovered |
Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/55cda8c7125986e17d7e1825cba413bd94a35d02 | 2026-03-01 | |
| CVE-2026-32778.patch | copy prefix name to pool before lookup .. so that we cannot end up with a zombie PREFIX in the pool that has NULL for a name. |
laserbear <10689391+Laserbear@users.noreply.github.com> | no | upstream, https://github.com/libexpat/libexpat/commit/576b61e42feeea704253cb7c7bedb2eeb3754387 | 2026-03-08 | |
| CVE-2026-45186-1.patch | lib: Extract a constant for upcoming reuse | Sebastian Pipping <sebastian@pipping.org> | no | backport, https://github.com/libexpat/libexpat/pull/1216/commits/fb35f2d2040d114f355bae8a7450942533237530 | 2026-03-08 | |
| CVE-2026-45186-2.patch | lib: Introduce ELEMENT_TYPE.defaultAttsNames | Sebastian Pipping <sebastian@pipping.org> | no | backport, https://github.com/libexpat/libexpat/pull/1216/commits/7f0f1b9e70d937072d2e9e37ae9edf27784cc080 | 2026-03-08 | |
| CVE-2026-45186-3.patch | lib: Leverage ELEMENT_TYPE.defaultAttsNames for attribute collision detection .. to resolve quadratic runtime behavior |
Sebastian Pipping <sebastian@pipping.org> | no | backport, https://github.com/libexpat/libexpat/pull/1216/commits/4cd4eb0683e04cd45a2ffc81a08ca2a2663994b5 | 2026-03-08 | |
| CVE-2026-45186-4.patch | lib: Remove unnecessary `lookup` casts | Matthew Fernandez <matthew.fernandez@gmail.com> | no | backport, https://github.com/libexpat/libexpat/pull/1216/commits/57ccdbfd395d1785a6c1ad75901f9534aa1fdc56 | 2026-05-15 | |
| CVE-2026-66046-1.patch | lib: Rename hash table `defaultAttsNames` to `defaultAttForName` It was previously used as a "set". This prepares for the upcoming change to a true "dictionary". |
Sebastian Pipping <sebastian@pipping.org> | no | backport, https://github.com/libexpat/libexpat/commit/98f5acc146af76859cd7c345c0906e9e9e8ea656 | 2026-08-13 | |
| CVE-2026-66046-2.patch | lib: Migrate .isCdata lookup from a linear loop to a hash table lookup .. to resolve quadratic runtime |
Sebastian Pipping <sebastian@pipping.org> | no | backport, https://github.com/libexpat/libexpat/commit/f8f7c4ffd883e3c2c58f0ebb49416a6c1d248738 | 2026-08-13 | |
| CVE-2026-56406-2.patch | lib: Make internal `m_position` use `uint64_t` to support >4 GiB documents | Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/pull/1300 | 2026-08-06 | |
| CVE-2026-56406-3.patch | lib: Make internal `m_parseEndByteIndex` use `uint64_t` to support >2 GiB documents Fixes a regression from Expat 2.8.2. |
Evgeny Kotkov <kotkov@apache.org> | no | upstream, https://github.com/libexpat/libexpat/pull/1300 | 2026-08-06 | |
| CVE-2026-56407.patch | cap entity textLen against signed integer overflow | netliomax25-code <netliomax25@gmail.com> | no | upstream, https://github.com/libexpat/libexpat/commit/30c2fc179ce5d2b1b1bae30bbe0dfddeac894e13 | 2026-06-02 | |
| CVE-2026-56408.patch | lib: Waterproof `copyString` from integer overflow | Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/16e2efd867ea8567ffa012210b52ef5918e20817 | 2026-04-23 | |
| CVE-2026-56409.patch | xmlwf: protect output path join from integer overflow | netliomax25-code <netliomax25@gmail.com> | no | backport, https://github.com/libexpat/libexpat/commit/61f7cdda22546c4bee38dd2d3fa3d6e4aa64d33e | 2026-06-01 | |
| CVE-2026-56410-1.patch | xmlwf: protect resolveSystemId from integer overflow | netliomax25-code <netliomax25@gmail.com> | no | backport, https://github.com/libexpat/libexpat/commit/deeb97f7c88d17a16b0ea2521a13733abc283347 | 2026-05-29 | |
| CVE-2026-56410-2.patch | xmlwf: guard each operator in resolveSystemId length sum | netliomax25-code <netliomax25@gmail.com> | no | upstream, https://github.com/libexpat/libexpat/commit/cee20e91bf14dc7f6d2fc48f0d70d86b2dc3afea | 2026-05-30 | |
| CVE-2026-56411-0.patch | Free data->currentDoctypeName if notations is NULL We leak it and don't change it. |
AZero13 <gfunni234@gmail.com> | no | upstream, https://github.com/libexpat/libexpat/commit/2c90a96917f9b0222ef5955adf6f3ee504ad00b9 | 2025-12-28 | |
| CVE-2026-56411-1.patch | xmlwf: protect notation list allocation from integer overflow | netliomax25-code <netliomax25@gmail.com> | no | upstream, https://github.com/libexpat/libexpat/commit/528a4e5017e1bd3b48b689fd0c131df940ae3ea5 | 2026-06-02 | |
| CVE-2026-56412.patch | lib: guard XML_TOK_DATA_CHARS handler calls in doCdataSection() | hextheshadow <hextheshadow0x@gmail.com> | no | upstream, https://github.com/libexpat/libexpat/commit/d19e834794060d18c061d94452c35d725393ea58 | 2026-06-20 | |
| CVE-2026-76957.patch | Protect custom encoding callbacks from parser reentry | Darren Carreras <carrerasdarren@gmail.com> | no | upstream, https://github.com/libexpat/libexpat/pull/1322 | 2026-08-17 | |
| CVE-2026-72522.patch | Merge pull request #1296 from libexpat/mozilla-2053153 [CVE-2026-72522] Fix an OOB read and the resulting infinite loop in `*_toUtf16` functions |
Sebastian Pipping <sebastian@pipping.org> | no | backport, https://github.com/libexpat/libexpat/commit/27c6536c2bfa857b6678b1038d14f43fd65a4aa6 | 2026-08-10 | |
| CVE-2025-59375-1.patch | lib: Make function dtdCreate use macro MALLOC .. and give its body access to the parser for upcoming changes |
Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/0872c189db6e457084fca335662a9cb49e8ec4c7 | 2025-09-01 | |
| CVE-2025-59375-2.patch | lib: Make string pools use macros MALLOC, FREE, REALLOC | Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/8768dadae479d9f2e984b747fb2ba79bb78de94f | 2025-09-01 | |
| CVE-2025-59375-3.patch | lib: Make function hash tables use macros MALLOC and FREE | Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/4fc6f1ee9f2b282cfe446bf645c992e37f8c3e15 | 2025-09-01 | |
| CVE-2025-59375-4.patch | lib: Make function copyString use macro MALLOC | Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/51487ad9d760faa4809b0f8e189d2f666317e41a | 2025-09-01 | |
| CVE-2025-59375-5.patch | lib: Make function dtdCopy use macro MALLOC | Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/4e7a5d03daf672f20c73d40dc8970385c18b30d3 | 2025-09-01 | |
| CVE-2025-59375-6.patch | lib: Make function dtdDestroy use macro FREE | Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/53a3eda0ae2e0317afd071b72b41976053d82732 | 2025-09-01 | |
| CVE-2025-59375-7.patch | lib: Make function dtdReset use macro FREE | Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/b3f0bda5f5e979781469532f7c304f7e223568d5 | 2025-09-01 | |
| CVE-2026-50219-3.patch | lib: Register m_*Handler with handler call depth tracking - m_attlistDeclHandler - m_characterDataHandler - m_commentHandler - m_defaultHandler - m_elementDeclHandler - m_endCdataSectionHandler - m_endDoctypeDeclHandler - m_endElementHandler - m_endNamespaceDeclHandler - m_entityDeclHandler - m_externalEntityRefHandler - m_notationDeclHandler - m_notStandaloneHandler - m_processingInstructionHandler - m_skippedEntityHandler - m_startCdataSectionHandler - m_startDoctypeDeclHandler - m_startElementHandler - m_startNamespaceDeclHandler - m_unknownEncodingHandler - m_unparsedEntityDeclHandler - m_xmlDeclHandler |
Sebastian Pipping <sebastian@pipping.org> | no | backport, https://github.com/libexpat/libexpat/pull/1246/commits | 2026-05-26 | |
| CVE-2026-50219-4.patch | lib: Protect XML_* from being called from a handler - XML_GetBuffer - XML_Parse - XML_ParseBuffer - XML_ParserFree - XML_ParserReset |
Sebastian Pipping <sebastian@pipping.org> | no | backport, https://github.com/libexpat/libexpat/pull/1246/commits | 2026-05-26 | |
| CVE-2026-56131.patch | lib: protect XML_ResumeParser from being called from a handler The handler-reentrancy guards from CVE-2026-50219 cover XML_Parse, XML_ParseBuffer, XML_GetBuffer, XML_ParserFree and XML_ParserReset but not XML_ResumeParser, which drives the parser through callProcessor in the same way. |
netliomax25-code <netliomax25@gmail.com> | no | backport, https://github.com/libexpat/libexpat/pull/1267/commits | 2026-06-06 | |
| CVE-2026-56403-0.patch | lib: split inessential reuse of `n` in `storeAtts` This change is intended to reduce the diff of an upcoming commit. |
Matthew Fernandez <matthew.fernandez@gmail.com> | no | backport, https://github.com/libexpat/libexpat/commit/99256f5fc2885e2176c9c9dd14af8625deab02f2 | 2026-05-19 | |
| CVE-2026-56403-1.patch | lib: Protect function `storeAtts` from signed integer overflow | Sebastian Pipping <sebastian@pipping.org> | no | backport, https://github.com/libexpat/libexpat/commit/12dc6d8d3d65f79471a94d8565f6bf1cf245f648 | 2026-05-20 | |
| CVE-2026-56403-2.patch | xmlwf: Protect function `xcsdup` from signed integer overflow | Sebastian Pipping <sebastian@pipping.org> | no | backport, https://github.com/libexpat/libexpat/commit/147c8f36d6277d5c6011c098370a8362aed47b15 | 2026-05-22 | |
| CVE-2026-56404.patch | lib: protect function addBinding from signed integer overflow | netliomax25-code <netliomax25@gmail.com> | no | upstream, https://github.com/libexpat/libexpat/commit/babfc48090977cbf7be24b2c48f6053dca75c164 | 2026-05-28 | |
| CVE-2026-56405.patch | lib: Protect function getAttributeId from signed integer overflow | netliomax25-code <netliomax25@gmail.com> | no | upstream, https://github.com/libexpat/libexpat/commit/2c6c42d33689f6b266a5267b639e03cde17e53c0 | 2026-05-29 | |
| CVE-2026-56406-1.patch | lib: Copy overflow check from `XML_Parse` to `XML_ParseBuffer` | Sebastian Pipping <sebastian@pipping.org> | no | upstream, https://github.com/libexpat/libexpat/commit/99d8454fdf900a6d00c2a52748e6c0eeb507574d | 2026-05-31 | |
| CVE-2026-66046-3.patch | lib: Fix out-of-bounds read from hash table entries created by dtdCopy Commit f8f7c4ff grew the entries of ELEMENT_TYPE member .defaultAttForName from structure NAMED to the larger structure NAME_AND_DEFAULT_ATTRIBUTE and adjusted function defineAttribute accordingly, but function dtdCopy kept creating entries of size sizeof(NAMED). Because function lookup allocates exactly createSize bytes, function storeAtts reads member .attIndex past the end of those entries whenever attributes are parsed by a parser that was created by XML_ExternalEntityParserCreate. That out-of-bounds value is then used as an index into member .defaultAtts, so the effects range from silently not normalizing whitespace in attributes that are not of type CDATA, to dereferencing a wild pointer: a release build of master segfaults in function storeAtts on the document used by the new test. A zero-filled heap happens to yield index 0, which is why the existing tests did not catch this. Member .attIndex is now stored the way function defineAttribute stores it, i.e. keeping the index of the first declaration, so that a copied DTD resolves attributes exactly like the DTD that it was copied from. This was found while backporting the fix for CVE-2026-66046 onto Expat 2.6.4 for the OpenCloudOS Stream distribution. Only master is affected, no released version of Expat contains commit f8f7c4ff. |
Zeyou Liu <zeyouliu@tencent.com> | no | backport, https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf | 2026-08-20 | |
| CVE-2026-93990.patch | lib: reject UTF-16 high surrogate not followed by a low surrogate | Kartik Kenchi <netliomax25@gmail.com> | no | upstream, https://github.com/libexpat/libexpat/commit/0cfd15bdf4b2c22d6b0df73610709dfb60921091 | 2026-06-23 |
All known versions for source package 'expat'
- 2.8.5-2 (sid)
- 2.8.4-2 (forky)
- 2.8.3-1~deb13u1 (trixie, trixie-security)
- 2.5.0-1+deb12u4 (bookworm-security)
- 2.5.0-1+deb12u2 (bookworm)
