Описание
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing a specially crafted XML document that leverages insufficient entropy in the hash function. This can lead to hash flooding, a type of Denial of Service (DoS) attack, where the system becomes unresponsive or crashes due to excessive resource consumption.
Отчет
This Low impact denial of service flaw in libexpat could allow a remote attacker to cause the program consuming libexpat to become unresponsive or crash. This vulnerability requires the processing of a specially crafted XML document, which could lead to excessive resource consumption due to hash flooding.
Меры по смягчению последствий
Applications that process untrusted XML documents using libexpat should implement robust input validation to filter out malicious XML structures. Restricting access to services that process untrusted XML can also reduce the attack surface. If a service is affected, restarting it may be required after implementing input validation or access restrictions.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | expat | Fix deferred | ||
| Red Hat Enterprise Linux 6 | compat-expat1 | Fix deferred | ||
| Red Hat Enterprise Linux 6 | expat | Fix deferred | ||
| Red Hat Enterprise Linux 7 | expat | Fix deferred | ||
| Red Hat Enterprise Linux 8 | expat | Fix deferred | ||
| Red Hat Enterprise Linux 8 | mingw-expat | Fix deferred | ||
| Red Hat Enterprise Linux 9 | expat | Fix deferred | ||
| Red Hat Hardened Images | expat-main-2.8.0-0.1.hum1 | Fixed | RHSA-2026:11004 | 27.04.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
Связанные уязвимости
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
libexpat before 2.8.0 uses insufficient entropy, and thus hash floodin ...
libexpat before 2.7.6 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
EPSS
3.7 Low
CVSS3