Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libexpat | Libexpat_project | * | 2.8.3 (including) |
| Red Hat Enterprise Linux 8 | RedHat | expat-0:2.5.0-4.el8_10 | * |
| Red Hat Enterprise Linux 9 | RedHat | expat-0:2.5.0-6.el9_8.5 | * |
| Red Hat Enterprise Linux 9 | RedHat | expat-0:2.5.0-6.el9_8.5 | * |
| Red Hat Hardened Images | RedHat | expat-main-2.8.4-0.1.hum1 | * |
| Expat | Ubuntu | devel | * |
| Expat | Ubuntu | esm-infra-legacy/trusty | * |
| Expat | Ubuntu | esm-infra-legacy/xenial | * |
| Expat | Ubuntu | esm-infra/bionic | * |
| Expat | Ubuntu | esm-infra/focal | * |
| Expat | Ubuntu | jammy | * |
| Expat | Ubuntu | noble | * |
| Expat | Ubuntu | resolute | * |
| Expat | Ubuntu | upstream | * |
| Matanza | Ubuntu | devel | * |
| Matanza | Ubuntu | esm-apps/focal | * |
| Matanza | Ubuntu | esm-apps/jammy | * |
| Matanza | Ubuntu | esm-apps/noble | * |
| Matanza | Ubuntu | esm-apps/resolute | * |
| Matanza | Ubuntu | jammy | * |
| Matanza | Ubuntu | noble | * |
| Matanza | Ubuntu | resolute | * |