MGASA-2026-0031 - Updated expat packages fix security vulnerabilities. MGASA-2026-0031 - Updated expat packages fix security vulnerabilities Publication date: 04 Feb 2026 URL: https://advisories.mageia.org/MGASA-2026-0031.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-24515, CVE-2026-25210 Description: In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data. (CVE-2026-24515) In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation. (CVE-2026-25210) References: - https://bugs.mageia.org/show_bug.cgi?id=35089 - https://www.openwall.com/lists/oss-security/2026/01/31/1 - https://www.cve.org/CVERecord?id=CVE-2026-24515 - https://www.cve.org/CVERecord?id=CVE-2026-25210 SRPMS: - 9/core/expat-2.7.4-1.mga9 . Updated expat packages addressing critical issues fixed for Mageia 9, preserving security and stability for users.. Mageia Expat Security Advisory, CVE-2026-24515, CVE-2026-25210, Mageia 9 update, important security issue. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.