An XML parser library
Go to file
RHEL Packaging Agent e7a9f5d2e1 expat: backport CVE-2026-45186 fix (attribute collision check DoS)
Backport upstream PR #1216 to fix CVE-2026-45186, which
resolves a quadratic runtime issue in attribute collision
detection. The patch introduces ELEMENT_TYPE.defaultAttsNames
in xmlparse.c and adds 7 new regression test cases for
duplicate attribute name handling. Test changes were adapted
from upstream's split test files to the 2.5.0 runtests.c
layout.

CVE: CVE-2026-45186
Upstream patches:
 - https://github.com/libexpat/libexpat/pull/1216.patch
Resolves: RHEL-177979

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
2026-05-28 11:42:32 +00:00
.fmf Add fmf plans and update gating.yaml 2024-09-11 16:05:14 +02:00
.gitignore Rebase to version 2.5.0 2025-11-19 10:34:09 +01:00
ci.fmf Add fmf plans and update gating.yaml 2024-09-11 16:05:14 +02:00
expat-2.5.0-CVE-2023-52425.patch Rebase to version 2.5.0 2025-11-19 10:34:09 +01:00
expat-2.5.0-CVE-2024-8176.patch Rebase to version 2.5.0 2025-11-19 10:34:09 +01:00
expat-2.5.0-CVE-2024-28757.patch Rebase to version 2.5.0 2025-11-19 10:34:09 +01:00
expat-2.5.0-CVE-2024-45490.patch Rebase to version 2.5.0 2025-11-19 10:34:09 +01:00
expat-2.5.0-CVE-2024-45491.patch Rebase to version 2.5.0 2025-11-19 10:34:09 +01:00
expat-2.5.0-CVE-2024-45492.patch Rebase to version 2.5.0 2025-11-19 10:34:09 +01:00
expat-2.5.0-CVE-2024-50602.patch Rebase to version 2.5.0 2025-11-19 10:34:09 +01:00
expat-2.5.0-CVE-2025-59375.patch Rebase to version 2.5.0 2025-11-19 10:34:09 +01:00
expat-2.5.0-CVE-2026-45186.patch expat: backport CVE-2026-45186 fix (attribute collision check DoS) 2026-05-28 11:42:32 +00:00
expat.spec expat: backport CVE-2026-45186 fix (attribute collision check DoS) 2026-05-28 11:42:32 +00:00
gating.yaml Add fmf plans and update gating.yaml 2024-09-11 16:05:14 +02:00
plans.fmf Add fmf plans and update gating.yaml 2024-09-11 16:05:14 +02:00
sources Rebase to version 2.5.0 2025-11-19 10:34:09 +01:00