REDHAT-BUG-2395108: High severity Expat libexpat vulnerability
Published Sep 15, 2025
·Updated
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
Affected Software
1 affected component
Expat libexpat<2.7.2
Event History
Sep 15, 2025
Data Sourced
via Red Hat·03:01 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2395108?
The severity of REDHAT-BUG-2395108 is considered high due to potential exploitation through large dynamic memory allocations.
2
How do I fix REDHAT-BUG-2395108?
To fix REDHAT-BUG-2395108, upgrade to Expat version 2.7.2 or later.
3
What versions of libexpat are affected by REDHAT-BUG-2395108?
REDHAT-BUG-2395108 affects Expat libexpat versions prior to 2.7.2.
4
What are the potential consequences of exploiting REDHAT-BUG-2395108?
Exploiting REDHAT-BUG-2395108 can lead to denial of service due to excessive memory allocation.
5
Who can be impacted by REDHAT-BUG-2395108?
Any application using vulnerable versions of Expat libexpat for XML parsing could be impacted by REDHAT-BUG-2395108.