CVE-2026-25210
Published: January 31, 2026Last modified: February 3, 2026
Description
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 6.9 |
| Attack Vector | LOCAL |
| Attack complexity | HIGH |
| Privileges required | NONE |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity impact | HIGH |
| Availability impact | LOW |
| Vector | CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | expat | Fixed (2.7.4-r0) |
| 25 LTS | expat | Fixed (2.7.4-r0) | |
| Stream | expat | Fixed (2.7.4-r0) | |
| Hardened Containers | 23 LTS | expat | Fixed (2.7.4-r0) |
| 25 LTS | expat | Fixed (2.7.4-r0) | |
| Stream | expat | Fixed (2.7.4-r0) |