In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropys return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.
The product does not properly check when a function or operation returns a value that is legitimate for the function, but is not expected by the product.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libexpat | Libexpat_project | 2.8.2 (including) | 2.8.4 (excluding) |
| Red Hat Hardened Images | RedHat | expat-main-2.8.3-0.1.1.hum1 | * |
| Red Hat Hardened Images | RedHat | expat-main-2.8.4-0.1.hum1 | * |
| Expat | Ubuntu | devel | * |
| Expat | Ubuntu | upstream | * |
| Matanza | Ubuntu | devel | * |
| Matanza | Ubuntu | esm-apps/focal | * |
| Matanza | Ubuntu | esm-apps/jammy | * |
| Matanza | Ubuntu | esm-apps/noble | * |
| Matanza | Ubuntu | esm-apps/resolute | * |
| Matanza | Ubuntu | jammy | * |
| Matanza | Ubuntu | noble | * |
| Matanza | Ubuntu | resolute | * |