Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56407

Опубликовано: 21 июн. 2026
Источник: redhat
CVSS3: 6.9
EPSS Низкий

Описание

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

An integer overflow exists in libexpat's doProlog function due to improper handling of entity value lengths. A local attacker could exploit this to execute arbitrary code or access sensitive system data.

Отчет

This Moderate severity flaw in libexpat, an XML parsing library, is due to an integer overflow during the processing of entity declarations. While exploitation could lead to arbitrary code execution or information disclosure, the attack requires local access and has high complexity, limiting its immediate impact on typical Red Hat deployments.

Меры по смягчению последствий

To prevent exploitation explicitly disable all internal and external XML entity processing within your application's parser configuration. Additionally, use a Web Application Firewall (WAF) to strictly limit the maximum size of incoming XML payloads to prevent the overflow trigger.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10expatFix deferred
Red Hat Enterprise Linux 10firefoxFix deferred
Red Hat Enterprise Linux 10thunderbirdFix deferred
Red Hat Enterprise Linux 6compat-expat1Out of support scope
Red Hat Enterprise Linux 6expatOut of support scope
Red Hat Enterprise Linux 7expatOut of support scope
Red Hat Enterprise Linux 7firefoxOut of support scope
Red Hat Enterprise Linux 8expatFix deferred
Red Hat Enterprise Linux 8firefoxFix deferred
Red Hat Enterprise Linux 8mingw-expatFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2491184libexpat: libexpat: Arbitrary code execution due to integer overflow

EPSS

Процентиль: 3%
0.00124
Низкий

6.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.9
ubuntu
около 1 месяца назад

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

CVSS3: 6.9
nvd
около 1 месяца назад

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

CVSS3: 6.9
msrc
около 1 месяца назад

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

CVSS3: 6.9
debian
около 1 месяца назад

libexpat before 2.8.2 has an integer overflow in doProlog that is rela ...

CVSS3: 6.9
github
около 1 месяца назад

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

EPSS

Процентиль: 3%
0.00124
Низкий

6.9 Medium

CVSS3