AI analysis
libexpat, one of the most widely used open-source XML parsing libraries, contains an integer overflow (CWE-190) in the expat_realloc() function when computing allocation sizes on 32-bit platforms, affecting versions 2.7.2 through 2.8.5. An attacker triggers the flaw by supplying maliciously crafted XML to any application that parses untrusted input with a vulnerable 32-bit build of the library, causing the size calculation to wrap around and resulting in an undersized heap allocation, heap buffer overflow, and memory corruption. The practical impact scored by CVSS 4.0 (8.2, high) is a severe availability impact — denial of service of the parsing process — via a network-reachable vector requiring no privileges or user interaction, though the attack requires high complexity and specific preconditions. Any software vendor or embedded device that statically links or ships a vulnerable 32-bit libexpat and parses attacker-controlled XML is affected, while 64-bit builds are not exposed to this specific flaw. No public proof-of-concept exists, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and no exploitation in the wild has been reported.
What to do: Upgrade any libexpat 2.7.2–2.8.5 deployment to the first fixed release issued after 2.8.5 as soon as it ships from the libexpat project or your OS/package vendor. Audit embedded products, IoT firmware, and legacy applications that statically link libexpat on 32-bit architectures and that accept XML from network clients, since bundled copies will not update via system package managers. As interim mitigations, validate or limit the size of XML input before parsing and monitor parsing processes for crashes until patched builds are deployed.
Affected
| libexpat project libexpat (expat XML parser library) | 2.7.2 through 2.8.5, on 32-bit platforms only |
Estimated exposure
massLikely tens of millions of installations potentially embed a vulnerable version, with an unknown but far smaller subset running 32-bit builds that parse… — libexpat is bundled by default in major Linux distributions, language runtimes, and thousands of desktop and server applications, and 32-bit builds remain common on embedded and IoT ARM devices, so the raw install base is enormous even…
Description
libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service.