Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-25210

Опубликовано: 30 янв. 2026
Источник: redhat
CVSS3: 6.9
EPSS Низкий

Описание

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

A flaw was found in libexpat. A local attacker could exploit an integer overflow vulnerability in the doContent function. This flaw occurs because the buffer size is not properly determined during tag buffer reallocation, which can lead to memory corruption. Successful exploitation may result in information disclosure and data integrity issues.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10expatNot affected
Red Hat Enterprise Linux 6compat-expat1Not affected
Red Hat Enterprise Linux 6expatNot affected
Red Hat Enterprise Linux 7expatNot affected
Red Hat Enterprise Linux 8expatNot affected
Red Hat Enterprise Linux 8mingw-expatNot affected
Red Hat Enterprise Linux 9expatNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2435454libexpat: libexpat: Information disclosure and data integrity issues due to integer overflow in buffer reallocation

EPSS

Процентиль: 0%
0.00006
Низкий

6.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.9
ubuntu
около 2 месяцев назад

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

CVSS3: 6.9
nvd
около 2 месяцев назад

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

CVSS3: 6.9
debian
около 2 месяцев назад

In libexpat before 2.7.4, the doContent function does not properly det ...

CVSS3: 7.8
redos
18 дней назад

Уязвимость expat

CVSS3: 6.9
github
около 2 месяцев назад

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

EPSS

Процентиль: 0%
0.00006
Низкий

6.9 Medium

CVSS3