When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Python | Python | * | 3.10.0 (excluding) |
| Python | Python | 3.13.0 (including) | 3.13.13 (excluding) |
| Python | Python | 3.14.0 (including) | 3.14.4 (excluding) |
| Python | Python | 3.15.0-alpha1 (including) | 3.15.0-alpha1 (including) |
| Python | Python | 3.15.0-alpha2 (including) | 3.15.0-alpha2 (including) |
| Python | Python | 3.15.0-alpha3 (including) | 3.15.0-alpha3 (including) |
| Python | Python | 3.15.0-alpha4 (including) | 3.15.0-alpha4 (including) |
| Python | Python | 3.15.0-alpha5 (including) | 3.15.0-alpha5 (including) |
| Python | Python | 3.15.0-alpha6 (including) | 3.15.0-alpha6 (including) |
| Python | Python | 3.15.0-alpha7 (including) | 3.15.0-alpha7 (including) |
| Red Hat Enterprise Linux 10 | RedHat | python3.14-0:3.14.4-2.el10_2 | * |
| Red Hat Enterprise Linux 10 | RedHat | python3.12-0:3.12.13-2.el10_2 | * |
| Red Hat Enterprise Linux 8 | RedHat | python3.12-0:3.12.13-2.el8_10 | * |
| Red Hat Enterprise Linux 9 | RedHat | python3.14-0:3.14.4-2.el9_8 | * |
| Red Hat Enterprise Linux 9 | RedHat | python3.12-0:3.12.13-2.el9_8 | * |
| Red Hat Hardened Images | RedHat | python3-13-main-3.13.13-1.hum1 | * |
| Red Hat Hardened Images | RedHat | python3-14-main-3.14.4-1.hum1 | * |
| Red Hat Hardened Images | RedHat | python3-11-main-3.11.15-4.hum1 | * |
| Red Hat Hardened Images | RedHat | python3-12-main-3.12.13-3.hum1 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/installer-rhel9:1779798165 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/rhua-rhel9:1779798222 | * |
| Python2.7 | Ubuntu | esm-infra/xenial | * |
| Python3.13 | Ubuntu | upstream | * |
| Python3.14 | Ubuntu | upstream | * |
| Python3.5 | Ubuntu | esm-infra/xenial | * |