Reference: https://www.openwall.com/lists/oss-security/2026/03/17/10
Source RPM: (none) => expat-2.7.4-1.mga10.src.rpm, expat-2.7.4-1.mga9.src.rpmCVE: (none) => CVE-2026-32776, CVE-2026-32777, CVE-2026-32778Status comment: (none) => Fixed upstream in 2.7.5Whiteboard: (none) => MGA9TOOFlags: (none) => affects_mga9+
For Cauldron, I asked for a freeze move. Suggested advisory: ======================== The updated packages fix security vulnerabilities: libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content. (CVE-2026-32776) libexpat before 2.7.5 allows an infinite loop while parsing DTD content. (CVE-2026-32777) libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition. (CVE-2026-32778) References: https://www.openwall.com/lists/oss-security/2026/03/17/10 ======================== Updated packages in core/updates_testing: ======================== expat-2.7.5-1.mga9 lib(64)expat1-2.7.5-1.mga9 lib(64)expat-devel-2.7.5-1.mga9 from SRPM: expat-2.7.5-1.mga9.src.rpm
Status: NEW => ASSIGNEDSource RPM: expat-2.7.4-1.mga10.src.rpm, expat-2.7.4-1.mga9.src.rpm => expat-2.7.4-1.mga9.src.rpmStatus comment: Fixed upstream in 2.7.5 => (none)Flags: affects_mga9+ => (none)Version: Cauldron => 9Whiteboard: MGA9TOO => (none)Assignee: bugsquad => qa-bugs
MGA9-64 server Plasma Wayland on Compaq H000SB. No installation issues. Ref bug 35089 and followed instructions from wiki: https://wiki.mageia.org/en/QA_procedure:Expat $ python testexpat.py Tested OK $ xmlwf /etc/xml/catalog $ xmlwf /etc/passwd /etc/passwd:1:16: not well-formed (invalid token) So OK as before
CC: (none) => herman.viaeneWhiteboard: (none) => MGA9-64-OKFlags: (none) => test_passed_mga9_64+
Validating.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
Keywords: (none) => advisory
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2026-0061.html
Status: ASSIGNED => RESOLVEDResolution: (none) => FIXED