Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update: expat #1528

Closed
dongsupark opened this issue Sep 2, 2024 · 2 comments · Fixed by flatcar/scripts#2320
Closed

update: expat #1528

dongsupark opened this issue Sep 2, 2024 · 2 comments · Fixed by flatcar/scripts#2320
Labels
advisory security advisory cvss/CRITICAL >= 9 assessed CVSS security security concerns

Comments

@dongsupark
Copy link
Member

dongsupark commented Sep 2, 2024

Name: expat
CVEs: CVE-2024-45490
CVSSs: 9.8
Action Needed: update to >= 2.6.3

Summary: An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

refmap.gentoo: https://bugs.gentoo.org/938894

@dongsupark dongsupark added security security concerns advisory security advisory labels Sep 2, 2024
@dongsupark dongsupark moved this from 📝 Needs Triage to 🪵Backlog in Flatcar tactical, release planning, and roadmap Sep 3, 2024
@dongsupark dongsupark added the cvss/CRITICAL >= 9 assessed CVSS label Sep 6, 2024
@dongsupark dongsupark moved this from 🪵Backlog to 🌱 Upcoming / Focus in Flatcar tactical, release planning, and roadmap Sep 6, 2024
@dongsupark
Copy link
Member Author

Cvss score 9.8, critical.

@krnowak
Copy link
Member

krnowak commented Oct 2, 2024

Backports for other channels:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
advisory security advisory cvss/CRITICAL >= 9 assessed CVSS security security concerns
Projects
Development

Successfully merging a pull request may close this issue.

2 participants