Advisories ยป MGASA-2025-0109

Updated expat packages fix security vulnerability

Publication date: 22 Mar 2025
Modification date: 17 Oct 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-8176

Description

Improper restriction of xml entity expansion depth in libexpat.
(CVE-2024-8176)
NOTE: upstream deemed this fix incomplete after it was initially pushed. The
complete fix was submitted along with the fix for CVE-2025-59375.
                

References

SRPMS

9/core