USN-7145-1: Expat vulnerability
Published Dec 10, 2024
·Updated
It was discovered that Expat did not properly handle its internal state when attempting to resume an unstarted parser. An attacker could use this issue to cause a denial of service (application crash).
Affected Software
50 affected componentsFixes available
All of the following
ubuntu/expat<2.6.2-2ubuntu0.1
2.6.2-2ubuntu0.1
Ubuntu Ubuntu=24.10
All of the following
ubuntu/libexpat1<2.6.2-2ubuntu0.1
2.6.2-2ubuntu0.1
Ubuntu Ubuntu=24.10
All of the following
ubuntu/libexpat1-dev<2.6.2-2ubuntu0.1
2.6.2-2ubuntu0.1
Ubuntu Ubuntu=24.10
All of the following
ubuntu/expat<2.6.1-2ubuntu0.2
2.6.1-2ubuntu0.2
Ubuntu Ubuntu=24.04
All of the following
ubuntu/libexpat1<2.6.1-2ubuntu0.2
2.6.1-2ubuntu0.2
Ubuntu Ubuntu=24.04
All of the following
ubuntu/libexpat1-dev<2.6.1-2ubuntu0.2
2.6.1-2ubuntu0.2
Ubuntu Ubuntu=24.04
All of the following
ubuntu/expat<2.4.7-1ubuntu0.5
2.4.7-1ubuntu0.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libexpat1<2.4.7-1ubuntu0.5
2.4.7-1ubuntu0.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libexpat1-dev<2.4.7-1ubuntu0.5
2.4.7-1ubuntu0.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/expat<2.2.9-1ubuntu0.8
2.2.9-1ubuntu0.8
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libexpat1<2.2.9-1ubuntu0.8
2.2.9-1ubuntu0.8
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libexpat1-dev<2.2.9-1ubuntu0.8
2.2.9-1ubuntu0.8
Ubuntu Ubuntu=20.04
All of the following
ubuntu/expat<2.2.5-3ubuntu0.9+esm2
2.2.5-3ubuntu0.9+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libexpat1<2.2.5-3ubuntu0.9+esm2
2.2.5-3ubuntu0.9+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libexpat1-dev<2.2.5-3ubuntu0.9+esm2
2.2.5-3ubuntu0.9+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/expat<2.1.0-7ubuntu0.16.04.5+esm10
2.1.0-7ubuntu0.16.04.5+esm10
Ubuntu Ubuntu=16.04
All of the following
ubuntu/lib64expat1<2.1.0-7ubuntu0.16.04.5+esm10
2.1.0-7ubuntu0.16.04.5+esm10
Ubuntu Ubuntu=16.04
All of the following
ubuntu/lib64expat1-dev<2.1.0-7ubuntu0.16.04.5+esm10
2.1.0-7ubuntu0.16.04.5+esm10
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libexpat1<2.1.0-7ubuntu0.16.04.5+esm10
2.1.0-7ubuntu0.16.04.5+esm10
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libexpat1-dev<2.1.0-7ubuntu0.16.04.5+esm10
2.1.0-7ubuntu0.16.04.5+esm10
Ubuntu Ubuntu=16.04
All of the following
ubuntu/expat<2.1.0-4ubuntu1.4+esm10
2.1.0-4ubuntu1.4+esm10
Ubuntu Ubuntu=14.04
All of the following
ubuntu/lib64expat1<2.1.0-4ubuntu1.4+esm10
2.1.0-4ubuntu1.4+esm10
Ubuntu Ubuntu=14.04
All of the following
ubuntu/lib64expat1-dev<2.1.0-4ubuntu1.4+esm10
2.1.0-4ubuntu1.4+esm10
Ubuntu Ubuntu=14.04
All of the following
ubuntu/libexpat1<2.1.0-4ubuntu1.4+esm10
2.1.0-4ubuntu1.4+esm10
Ubuntu Ubuntu=14.04
All of the following
ubuntu/libexpat1-dev<2.1.0-4ubuntu1.4+esm10
2.1.0-4ubuntu1.4+esm10
Ubuntu Ubuntu=14.04
Event History
Dec 10, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7145-1?
The severity of USN-7145-1 is categorized as a denial of service vulnerability.
2
How do I fix USN-7145-1?
To fix USN-7145-1, update the Expat package to version 2.6.2-2ubuntu0.1 or a later version.
3
Which versions of Ubuntu are affected by USN-7145-1?
USN-7145-1 affects Ubuntu versions 20.04, 22.04, 24.04, and 24.10.
4
What type of vulnerability is USN-7145-1?
USN-7145-1 is a denial of service vulnerability due to improper handling of internal state in Expat.
5
Can USN-7145-1 lead to remote exploits?
No, USN-7145-1 specifically leads to application crashes and does not allow for remote code execution.