openSUSE 16 Security Update : expat (openSUSE-SU-2026:21945-1)

high Nessus Plugin ID 350766

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21945-1 advisory.

- CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263).
- CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input (bsc#1264713).
- CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631).
- CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation (bsc#1268572).
- CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer overflows (bsc#1268573).
- CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code execution (bsc#1275096).
- CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory corruption, and application crashes (bsc#1275096).
- CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary code execution (bsc#1275096).
- CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and application crashes (bsc#1275096).
- CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial of service (bsc#1275096).
- CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes (bsc#1275096).
- CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and arbitrary file write conditions (bsc#1275096).
- CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information disclosure, and potential code execution (bsc#1275096).
- CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and denial of service (bsc#1275096).
- CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free conditions and arbitrary code execution (bsc#1275096).
- CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c (bsc#1275732).
- CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing (bsc#1275594).
- CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption (bsc#1275915).
- CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted X (bsc#1275860).
- CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks.
(bsc#1275859).

Changes for expat:

- Updated to version 2.8.4

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected expat, libexpat-devel and / or libexpat1 packages.

See Also

https://bugzilla.suse.com/1262263

https://bugzilla.suse.com/1264713

https://bugzilla.suse.com/1267631

https://bugzilla.suse.com/1268572

https://bugzilla.suse.com/1268573

https://bugzilla.suse.com/1275096

https://bugzilla.suse.com/1275594

https://bugzilla.suse.com/1275732

https://bugzilla.suse.com/1275859

https://bugzilla.suse.com/1275860

https://bugzilla.suse.com/1275915

https://www.suse.com/security/cve/CVE-2026-41080

https://www.suse.com/security/cve/CVE-2026-45186

https://www.suse.com/security/cve/CVE-2026-50219

https://www.suse.com/security/cve/CVE-2026-56131

https://www.suse.com/security/cve/CVE-2026-56132

https://www.suse.com/security/cve/CVE-2026-56403

https://www.suse.com/security/cve/CVE-2026-56404

https://www.suse.com/security/cve/CVE-2026-56405

https://www.suse.com/security/cve/CVE-2026-56406

https://www.suse.com/security/cve/CVE-2026-56407

https://www.suse.com/security/cve/CVE-2026-56408

https://www.suse.com/security/cve/CVE-2026-56409

https://www.suse.com/security/cve/CVE-2026-56410

https://www.suse.com/security/cve/CVE-2026-56411

https://www.suse.com/security/cve/CVE-2026-56412

https://www.suse.com/security/cve/CVE-2026-66046

https://www.suse.com/security/cve/CVE-2026-72522

https://www.suse.com/security/cve/CVE-2026-76641

https://www.suse.com/security/cve/CVE-2026-76956

https://www.suse.com/security/cve/CVE-2026-76957

Plugin Details

Severity: High

ID: 350766

File Name: openSUSE-2026-21945-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/26/2026

Updated: 9/26/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.15

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-76957

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 7.7

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-76641

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:expat, p-cpe:/a:novell:opensuse:libexpat-devel, p-cpe:/a:novell:opensuse:libexpat1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/24/2026

Vulnerability Publication Date: 4/16/2026

Reference Information

CVE: CVE-2026-41080, CVE-2026-45186, CVE-2026-50219, CVE-2026-56131, CVE-2026-56132, CVE-2026-56403, CVE-2026-56404, CVE-2026-56405, CVE-2026-56406, CVE-2026-56407, CVE-2026-56408, CVE-2026-56409, CVE-2026-56410, CVE-2026-56411, CVE-2026-56412, CVE-2026-66046, CVE-2026-72522, CVE-2026-76641, CVE-2026-76956, CVE-2026-76957

IAVA: 2026-A-0407-S, 2026-A-0451, 2026-A-0650-S, 2026-A-0899-S, 2026-A-0925-S