AI analysis
libexpat before commit 13c5f63 has a heap buffer over-read (CWE-125) in xmlparse.c. XML_ParseBuffer advances parser->m_bufferEnd by a caller-supplied length that is not checked against the allocated buffer size, so repeated calls can move that pointer past the heap allocation and later parsing reads adjacent memory. The path requires a parse buffer to already exist, which happens after XML_GetBuffer or after an earlier XML_Parse that allocated the buffer; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. The over-read can disclose neighboring heap contents to the calling application, including heap, libc, and code pointers that weaken ASLR and can support further attacks, with high confidentiality impact and low availability impact. The issue is fixed in libexpat 2.9.0; it is not on the CISA KEV list and no public proof of concept is known.
What to do: Upgrade libexpat to 2.9.0 or any build that includes commit 13c5f63, then rebuild or update applications that link against it. Until then, callers of XML_ParseBuffer should pass only a length that does not exceed the buffer obtained from XML_GetBuffer. No public proof of concept or confirmed in-the-wild exploitation is known.
Affected
| libexpat project libexpat | before commit 13c5f63 (fixed in 2.9.0) |
Estimated exposure
masshundreds of millions of systems and applications (not all reachable via XML_ParseBuffer) — libexpat is a foundational XML parser shipped in major operating-system distributions and embedded in widely used software such as browsers and language runtimes, so installed copies are on the order of hundreds of millions even though…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives.