Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-32778

Опубликовано: 16 мар. 2026
Источник: debian
EPSS Низкий

Описание

libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
expatfixed2.7.5-1package

Примечания

  • https://github.com/libexpat/libexpat/pull/1163

  • Fixed by: https://github.com/libexpat/libexpat/commit/576b61e42feeea704253cb7c7bedb2eeb3754387

  • Test: https://github.com/libexpat/libexpat/commit/d5fa769b7a7290a7e2c4a0b2287106dec9b3c030

EPSS

Процентиль: 2%
0.00013
Низкий

Связанные уязвимости

CVSS3: 2.9
ubuntu
10 дней назад

libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.

CVSS3: 5.1
redhat
10 дней назад

A flaw was found in libexpat. This vulnerability allows an attacker to trigger a NULL pointer dereference in the `setContext` function. This occurs when the system attempts to retry an operation after an out-of-memory condition, which can lead to a Denial of Service (DoS) for the affected application.

CVSS3: 2.9
nvd
10 дней назад

libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.

msrc
8 дней назад

Описание отсутствует

CVSS3: 2.9
github
10 дней назад

libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.

EPSS

Процентиль: 2%
0.00013
Низкий