Back

MEDIUM

expat: Stack exhaustion in doctype parsing

Published Feb 18, 2022

Description

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

Affected products

Remediation

Red Hat statement

This flaw affects applications that leverage expat to parse untrusted XML files. Applications which only parse trusted XML files or do not process XML files at all are not affected by this flaw.

Red Hat mitigation

There is no known mitigation other than restricting applications using the expat library from processing untrusted XML content.

Weaknesses (2)

References (16)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Feb 18, 2022
Updated May 30, 2025
Reserved Feb 18, 2022

CISA Vulnrichment

Updated May 30, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Feb 19, 2022
Bugzilla 2056350

ENISA EUVD

Assigner mitre
Published Feb 18, 2022
Updated May 30, 2025

GitHub

No data