PT-2026-4328 · Libexpat+4 · Libexpat+4
Carnil
+1
·
Published
2026-01-01
·
Updated
2026-05-26
·
CVE-2026-24515
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libexpat versions prior to 2.7.4
Description
The issue resides in the
XML ExternalEntityParserCreate function. It does not properly copy user data for unknown encoding handlers, potentially leading to memory corruption. Reports indicate a critical impact on Linux distributions and applications, with the possibility of Remote Code Execution (RCE). The issue is described as an XML External Entity (XXE) flaw.Recommendations
Versions prior to 2.7.4 should be updated to version 2.7.4 or later.
Fix
RCE
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Aix
Linuxmint
Red Os
Ubuntu
Libexpat