Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-72522

Опубликовано: 10 авг. 2026
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.

A flaw in libexpat's _toUtf16 functions mishandles Unicode low surrogates by treating them as high surrogates. An attacker can exploit the resulting out-of-bounds read to trigger an infinite loop, causing a denial of service (DoS).

Отчет

A denial of service (DoS) flaw was found in libexpat's handling of Unicode surrogate pairs. An attacker providing specially crafted XML input to an application parsing untrusted data can trigger an out-of-bounds read and an infinite loop, leading to high CPU usage and system resource exhaustion.

Меры по смягчению последствий

Limit exposure by restricting the parsing of untrusted or unverified XML inputs, and validate incoming XML documents for malformed character sequences before processing. Additionally, enforce process-level CPU resource limits and parsing timeouts to prevent system-wide Denial of Service from infinite parsing loops.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10expatNot affected
Red Hat Enterprise Linux 10firefoxFix deferred
Red Hat Enterprise Linux 10thunderbirdFix deferred
Red Hat Enterprise Linux 6compat-expat1Not affected
Red Hat Enterprise Linux 6expatNot affected
Red Hat Enterprise Linux 7expatNot affected
Red Hat Enterprise Linux 7firefoxFix deferred
Red Hat Enterprise Linux 8expatNot affected
Red Hat Enterprise Linux 8firefoxFix deferred
Red Hat Enterprise Linux 8mingw-expatFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2513021expat: libexpat: Denial of Service due to incorrect Unicode surrogate handling

EPSS

Процентиль: 7%
0.00176
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
19 дней назад

libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.

CVSS3: 6.2
nvd
19 дней назад

libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.

CVSS3: 6.2
msrc
18 дней назад

libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.

CVSS3: 6.2
debian
19 дней назад

libexpat before 2.8.3 has an out-of-bounds read and resultant infinite ...

CVSS3: 6.2
github
19 дней назад

libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.

EPSS

Процентиль: 7%
0.00176
Низкий

6.2 Medium

CVSS3