Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76957

Опубликовано: 20 авг. 2026
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.

A flaw was found in libexpat. The library's handling of custom encoding callbacks lacks proper tracking of handler call depth, which can lead to a use-after-free vulnerability. This memory corruption flaw could allow a local attacker to cause a denial of service or potentially execute arbitrary code.

Отчет

Red Hat ships libexpat (packaged as "expat") across many products. All versions of expat prior to 2.8.4 are affected by this use-after-free vulnerability. Exploitation requires triggering the vulnerable code path through custom encoding callbacks, which is not a common usage pattern.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10expatFix deferred
Red Hat Enterprise Linux 10firefoxFix deferred
Red Hat Enterprise Linux 10thunderbirdFix deferred
Red Hat Enterprise Linux 6compat-expat1Fix deferred
Red Hat Enterprise Linux 6expatFix deferred
Red Hat Enterprise Linux 7expatFix deferred
Red Hat Enterprise Linux 7firefoxFix deferred
Red Hat Enterprise Linux 8expatFix deferred
Red Hat Enterprise Linux 8firefoxFix deferred
Red Hat Enterprise Linux 8mingw-expatFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2520125libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service

EPSS

Процентиль: 1%
0.00107
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
29 дней назад

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.

CVSS3: 4.9
nvd
29 дней назад

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.

msrc
27 дней назад

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.

CVSS3: 4.9
debian
29 дней назад

libexpat before 2.8.4 lacks handler call depth tracking with custom en ...

CVSS3: 4.9
github
28 дней назад

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.

EPSS

Процентиль: 1%
0.00107
Низкий

4.9 Medium

CVSS3