Slackware 1259 Published by

Slackware has released updated expat packages to address a critical security flaw in versions 15.0 and current development releases. The vulnerability stems from quadratic runtime complexity during attribute name collision checks, which attackers could exploit through moderately sized crafted XML files. Compressed XML payloads can make this denial of service threat even more efficient to execute. Administrators should download the patched binaries from official mirrors and apply them using standard upgrade procedures to secure their systems.

expat (SSA:2026-132-01)




expat (SSA:2026-132-01)


expat (SSA:2026-132-01)

New expat packages are available for Slackware 15.0 and -current to
fix a security issue.

Here are the details from the Slackware 15.0 ChangeLog:
+--------------------------+
patches/packages/expat-2.7.5-i586-2_slack15.0.txz: Rebuilt.
This update fixes a security issue:
Fix quadratic runtime from attribute name collision checks that allowed
denial of service attacks through moderately sized crafted XML input
(CWE-407). Please note that a layer of compression around XML can
significantly reduce the minimum attack payload size.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-45186
(* Security fix *)
+--------------------------+

Where to find the new packages:
+-----------------------------+

Thanks to the friendly folks at the OSU Open Source Lab
( http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/expat-2.7.5-i586-2_slack15.0.txz

Updated package for Slackware x86_64 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/expat-2.7.5-x86_64-2_slack15.0.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/expat-2.8.1-i686-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/expat-2.8.1-x86_64-1.txz

MD5 signatures:
+-------------+

Slackware 15.0 package:
6f8ef1e7eda54a2c02fab92f83172273 expat-2.7.5-i586-2_slack15.0.txz

Slackware x86_64 15.0 package:
67ee58733d413471994c96916886d207 expat-2.7.5-x86_64-2_slack15.0.txz

Slackware -current package:
807632543b921e7ec32af49ac1589abb l/expat-2.8.1-i686-1.txz

Slackware x86_64 -current package:
68e49a07e1200182f37e8026cdbaafb9 l/expat-2.8.1-x86_64-1.txz

Installation instructions:
+------------------------+

Upgrade the package as root:
# upgradepkg expat-2.7.5-i586-2_slack15.0.txz

+-----+

Slackware Linux Security Team
http://slackware.com/gpg-key