CVE-2026-25210

Published: January 31, 2026Last modified: February 3, 2026

Description

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

Severity score breakdown

ParameterValue
Base score6.9
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactLOW
VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSexpatFixed (2.7.4-r0)
25 LTSexpatFixed (2.7.4-r0)
StreamexpatFixed (2.7.4-r0)
Hardened Containers23 LTSexpatFixed (2.7.4-r0)
25 LTSexpatFixed (2.7.4-r0)
StreamexpatFixed (2.7.4-r0)

References

ON THIS PAGE