Описание
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
An XML Entity Expansion flaw was found in libexpat. This flaw allows an attacker to cause a denial of service when there is an isolated use of external parsers.
Отчет
This vulnerability is rated as a moderate severity because a flaw was found in the libexpat library in the xmlparse.c file, specifically in the handling of external parsers. The issue is an XML Entity Expansion flaw caused by the parser's failure to detect direct recursion when a parameter entity references itself in an external subset. An attacker can trigger this by submitting a specially crafted XML document, which creates an infinite processing loop, leading to uncontrolled resource consumption and causing a denial of service (DoS).
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | compat-expat1 | Not affected | ||
| Red Hat Enterprise Linux 6 | expat | Not affected | ||
| Red Hat Enterprise Linux 7 | expat | Not affected | ||
| Red Hat Enterprise Linux 8 | expat | Fixed | RHSA-2025:21776 | 19.11.2025 |
| Red Hat Enterprise Linux 9 | expat | Fixed | RHBA-2024:2518 | 30.04.2024 |
| Red Hat Enterprise Linux 9 | expat | Fixed | RHSA-2024:1530 | 26.03.2024 |
| Red Hat Enterprise Linux 9 | expat | Fixed | RHBA-2024:2518 | 30.04.2024 |
| Red Hat Enterprise Linux 9 | expat | Fixed | RHSA-2024:1530 | 26.03.2024 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | expat | Fixed | RHSA-2024:3926 | 13.06.2024 |
| Red Hat OpenShift Container Platform 4.15 | rhcos-415.92.202603101737 | Fixed | RHSA-2026:4419 | 19.03.2026 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
libexpat through 2.6.1 allows an XML Entity Expansion attack when ther ...
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
7.5 High
CVSS3