Alerts This Week
Warning Icon 1 758
Alerts This Week
Warning Icon 1 758

Debian 11: DLA-4145-1 urgent: expat XML parser vulnerability fix

debian lts
Calendar Grey April 30, 2025
Dist Debian Esm H88
Important patch released for Debian LTS addresses a crash vulnerability in the expat XML interpreter linked to XML_ResumeParser. Immediate upgrade advised!
An issue has been found in expat, an XML parsing C library

Summary

An issue has been found in expat, an XML parsing C library.
The issue is related to a crash within XML_ResumeParser() because
XML_StopParser() can stop/suspend an unstarted parser.


For Debian 11 bullseye, this problem has been fixed in version
2.2.10-2+deb11u7.

We recommend that you upgrade your expat packages.

For the detailed security status of expat please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/expat

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
critical
Lowest
Low
Medium
High
Critical

Package: expat
Version: 2.2.10-2+deb11u7
CVE ID: CVE-2024-50602

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here