Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56132

Опубликовано: 19 июн. 2026
Источник: redhat
CVSS3: 6.9
EPSS Низкий

Описание

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.

A flaw was found in libexpat, a library used for parsing XML data. An attacker could exploit a heap-based buffer overflow, a type of memory error, by providing specially crafted XML input. This vulnerability occurs when the library mishandles memory reallocation while processing XML, particularly when multiple parsers share data. Successful exploitation could allow the attacker to execute arbitrary code, access sensitive information, or cause the application to crash, leading to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10expatFix deferred
Red Hat Enterprise Linux 10firefoxUnder investigation
Red Hat Enterprise Linux 10thunderbirdUnder investigation
Red Hat Enterprise Linux 6compat-expat1Out of support scope
Red Hat Enterprise Linux 6expatOut of support scope
Red Hat Enterprise Linux 7expatFix deferred
Red Hat Enterprise Linux 7firefoxUnder investigation
Red Hat Enterprise Linux 8expatFix deferred
Red Hat Enterprise Linux 8firefoxUnder investigation
Red Hat Enterprise Linux 8mingw-expatFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2490669expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow

EPSS

Процентиль: 1%
0.00107
Низкий

6.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.9
ubuntu
около 1 месяца назад

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.

CVSS3: 6.9
nvd
около 1 месяца назад

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.

CVSS3: 6.9
msrc
около 1 месяца назад

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.

CVSS3: 6.9
debian
около 1 месяца назад

In libexpat before 2.8.2, there is a heap-based buffer overflow in doP ...

CVSS3: 6.9
github
около 1 месяца назад

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.

EPSS

Процентиль: 1%
0.00107
Низкий

6.9 Medium

CVSS3