Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56131

Опубликовано: 19 июн. 2026
Источник: redhat
CVSS3: 4.5
EPSS Низкий

Описание

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).

A use-after-free vulnerability in libexpat occurs because handler call depth isn't properly tracked when XML_ResumeParser is invoked during policy violations. This flaw can lead to information disclosure, data corruption, or denial of service.

Отчет

A Moderate impact use-after-free vulnerability exists in libexpat. This flaw, requiring local access and having high attack complexity, could lead to information disclosure, data corruption, or denial of service. The need for specific policy violations and local access substantially reduces the immediate risk in typical Red Hat environments.

Меры по смягчению последствий

To mitigate this vulnerability, avoid processing untrusted XML data in affected applications or ensure your implementation strictly validates and rejects malformed XML payloads before parsing.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10expatFix deferred
Red Hat Enterprise Linux 10firefoxFix deferred
Red Hat Enterprise Linux 10thunderbirdFix deferred
Red Hat Enterprise Linux 6compat-expat1Out of support scope
Red Hat Enterprise Linux 6expatOut of support scope
Red Hat Enterprise Linux 7expatOut of support scope
Red Hat Enterprise Linux 7firefoxOut of support scope
Red Hat Enterprise Linux 8expatFix deferred
Red Hat Enterprise Linux 8firefoxFix deferred
Red Hat Enterprise Linux 8mingw-expatFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2490668libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking

EPSS

Процентиль: 3%
0.00135
Низкий

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
около 1 месяца назад

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).

CVSS3: 4.9
nvd
около 1 месяца назад

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).

CVSS3: 4.9
msrc
около 1 месяца назад

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).

CVSS3: 4.9
debian
около 1 месяца назад

libexpat before 2.8.2 lacks handler call depth tracking for calls to X ...

CVSS3: 4.9
github
около 1 месяца назад

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).

EPSS

Процентиль: 3%
0.00135
Низкий

4.5 Medium

CVSS3