Expat versions 2.4.6 and 2.4.7 have been released, fixing regressions: https://blog.hartwork.org/posts/expat-2-4-6-released/ https://blog.hartwork.org/posts/expat-2-4-7-released/ https://github.com/libexpat/libexpat/blob/master/expat/Changes Ubuntu has issued an advisory for this today (March 10): https://ubuntu.com/security/notices/USN-5320-1 Mageia 8's backports of the security fixes are probably also affected by the regressions.
Whiteboard: (none) => MGA8TOOCC: (none) => nicolas.salguero, tmbStatus comment: (none) => Fixed upstream in 2.4.7
Suggested advisory: ======================== The updated packages fix regressions introduced by security fixes for CVE-2022-25313 and CVE-2022-25236. References: https://blog.hartwork.org/posts/expat-2-4-6-released/ https://blog.hartwork.org/posts/expat-2-4-7-released/ https://github.com/libexpat/libexpat/blob/master/expat/Changes https://ubuntu.com/security/notices/USN-5320-1 ======================== Updated packages in core/updates_testing: ======================== expat-2.2.10-1.4.mga8 lib(64)expat1-2.2.10-1.4.mga8 lib(64)expat-devel-2.2.10-1.4.mga8 from SRPM: expat-2.2.10-1.4.mga8.src.rpm
Status comment: Fixed upstream in 2.4.7 => (none)Whiteboard: MGA8TOO => (none)Version: Cauldron => 8Status: NEW => ASSIGNEDAssignee: bugsquad => qa-bugsSource RPM: expat-2.4.5-1.mga9.src.rpm => expat-2.2.10-1.3.mga8.src.rpm
No installation issues. I have no idea of how to test to see if the regressions have been fixed, so testing with the standard procedure from https://wiki.mageia.org/en/QA_procedure:Expat $ python testexpat.py Tested OK If that test is sufficient, then this update is OK for 64-bits.
CC: (none) => andrewsfarm
validating. Advisory in Comment 1.
Whiteboard: (none) => MGA8-64-OKKeywords: (none) => validated_updateCC: (none) => sysadmin-bugs
CC: (none) => davidwhodginsKeywords: (none) => advisory
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGAA-2022-0036.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED