Bugzilla – Bug 1196784
expat: [>=2.4.5] Fix to CVE-2022-25236 breaks biboumi, ClairMeta, jxmlease, libwbxml, openleadr-python, rnv, xmltodict
Last modified: 2022-11-17 16:12:41 UTC
It appears the recent security update for expat has broken many systems. See https://github.com/libexpat/libexpat/issues/572
So that would be bug CVE-2022-25236 / bug 1196025. Your fix: https://build.opensuse.org/request/show/959577
SUSE-SU-2022:0842-1: An update that solves one vulnerability and has one errata is now available. Category: security (important) Bug References: 1196025,1196784 CVE References: CVE-2022-25236 JIRA References: Sources used: SUSE OpenStack Cloud Crowbar 9 (src): expat-2.1.0-21.22.1 SUSE OpenStack Cloud Crowbar 8 (src): expat-2.1.0-21.22.1 SUSE OpenStack Cloud 9 (src): expat-2.1.0-21.22.1 SUSE OpenStack Cloud 8 (src): expat-2.1.0-21.22.1 SUSE Linux Enterprise Software Development Kit 12-SP5 (src): expat-2.1.0-21.22.1 SUSE Linux Enterprise Server for SAP 12-SP4 (src): expat-2.1.0-21.22.1 SUSE Linux Enterprise Server for SAP 12-SP3 (src): expat-2.1.0-21.22.1 SUSE Linux Enterprise Server 12-SP5 (src): expat-2.1.0-21.22.1 SUSE Linux Enterprise Server 12-SP4-LTSS (src): expat-2.1.0-21.22.1 SUSE Linux Enterprise Server 12-SP3-LTSS (src): expat-2.1.0-21.22.1 SUSE Linux Enterprise Server 12-SP3-BCL (src): expat-2.1.0-21.22.1 SUSE Linux Enterprise Server 12-SP2-BCL (src): expat-2.1.0-21.22.1 HPE Helion Openstack 8 (src): expat-2.1.0-21.22.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2022:0844-1: An update that solves one vulnerability and has one errata is now available. Category: security (important) Bug References: 1196025,1196784 CVE References: CVE-2022-25236 JIRA References: Sources used: openSUSE Leap 15.3 (src): expat-2.2.5-3.19.1
SUSE-SU-2022:0844-1: An update that solves one vulnerability and has one errata is now available. Category: security (important) Bug References: 1196025,1196784 CVE References: CVE-2022-25236 JIRA References: Sources used: SUSE Manager Server 4.1 (src): expat-2.2.5-3.19.1 SUSE Manager Retail Branch Server 4.1 (src): expat-2.2.5-3.19.1 SUSE Manager Proxy 4.1 (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise Server for SAP 15-SP2 (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise Server for SAP 15-SP1 (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise Server for SAP 15 (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise Server 15-SP2-LTSS (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise Server 15-SP2-BCL (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise Server 15-LTSS (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise Realtime Extension 15-SP2 (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise Micro 5.1 (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise Micro 5.0 (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): expat-2.2.5-3.19.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): expat-2.2.5-3.19.1 SUSE Enterprise Storage 7 (src): expat-2.2.5-3.19.1 SUSE Enterprise Storage 6 (src): expat-2.2.5-3.19.1 SUSE CaaS Platform 4.0 (src): expat-2.2.5-3.19.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
All patches were sent to all codestreams. Closing...
Hi David, could you please follow Stefan suggestion? Thanks
It seems everything is fixed now. Reassigning to Security.
SUSE-SU-2022:14934-1: An update that solves one vulnerability and has one errata is now available. Category: security (important) Bug References: 1196025,1196784 CVE References: CVE-2022-25236 JIRA References: Sources used: SUSE Linux Enterprise Server 11-SP4-LTSS (src): expat-2.0.1-88.42.22.1 SUSE Linux Enterprise Point of Sale 11-SP3 (src): expat-2.0.1-88.42.22.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): expat-2.0.1-88.42.22.1 SUSE Linux Enterprise Debuginfo 11-SP3 (src): expat-2.0.1-88.42.22.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:0844-2: An update that solves one vulnerability and has one errata is now available. Category: security (important) Bug References: 1196025,1196784 CVE References: CVE-2022-25236 JIRA References: Sources used: SUSE Linux Enterprise Micro 5.2 (src): expat-2.2.5-3.19.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Should be done. Closing.
This is an autogenerated message for OBS integration: This bug (1196784) was mentioned in https://build.opensuse.org/request/show/983632 Factory / python39
This is an autogenerated message for OBS integration: This bug (1196784) was mentioned in https://build.opensuse.org/request/show/983936 Factory / python310
SUSE-SU-2022:2294-1: An update that solves 5 vulnerabilities and has one errata is now available. Category: security (important) Bug References: 1196025,1196026,1196168,1196169,1196171,1196784 CVE References: CVE-2022-25235,CVE-2022-25236,CVE-2022-25313,CVE-2022-25314,CVE-2022-25315 JIRA References: Sources used: openSUSE Leap 15.4 (src): expat-2.4.4-150400.3.6.9 SUSE Linux Enterprise Module for Basesystem 15-SP4 (src): expat-2.4.4-150400.3.6.9 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
This is an autogenerated message for OBS integration: This bug (1196784) was mentioned in https://build.opensuse.org/request/show/1002448 Factory / python38
This is an autogenerated message for OBS integration: This bug (1196784) was mentioned in https://build.opensuse.org/request/show/1002501 Factory / python38