Sceawere
Vulnerability Detail
CVE-2026-102633UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
libexpat Integer Overflow Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.9
- Creation Date
- 8h ago
- Vendor
- libexpat
- Product
- libexpat
- Attack Type
- Integer Overflow or Wraparound
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.9",
"pubDate": "2026-09-29T17:17:06.980Z",
"pubdate": "2026-09-29T17:17:06.980Z",
"executiveSummary": "An integer overflow vulnerability exists in the expat_realloc() function within libexpat, affecting versions 2.7.2 through 2.8.5 on 32-bit platforms.\nThe vulnerability occurs during the computation of heap memory allocation sizes, potentially leading to heap buffer overflows, memory corruption, or application denial of service.\nAttackers can trigger this condition by supplying crafted, malicious XML input to applications utilizing the vulnerable libexpat library.\nThe flaw stems from an inadequate validation of input parameters before arithmetic operations that determine memory requirements, allowing for integer wrapping.\nSuccessful exploitation allows for memory corruption scenarios that can lead to arbitrary code execution or service termination depending on the application context.\nThe vulnerability is primarily restricted to 32-bit architectures where the address space is more susceptible to the wrapping behavior of the integer calculation.\nThere are no specific authentication or privilege requirements for exploitation, as the vector is triggered directly through the XML parser's processing of untrusted input.",
"technicalDetails": "The vulnerability resides in the internal memory management routines of libexpat, specifically within the expat_realloc() function. This function is responsible for resizing memory blocks during the parsing of complex XML structures.\nOn 32-bit systems, memory allocation sizes are represented using 32-bit unsigned integers. The root cause is a failure to perform overflow checks during the arithmetic operations used to calculate the new size for a memory block reallocation request. When an attacker provides an exceptionally large or complex XML input, the calculation (e.g., multiplier or addition) used to determine the buffer size can wrap around the maximum value of an unsigned 32-bit integer.\nThe attack flow initiates when a vulnerable application consumes a malicious XML document. As the libexpat parser encounters specific elements or structures that trigger an allocation request, it passes the size to expat_realloc(). Because the internal math overflows, the function requests a significantly smaller memory buffer from the system allocator than what is actually required for the parsed data.\nOnce the system returns the truncated, undersized heap buffer, subsequent parser operations attempt to write the full payload into this restricted space. This leads directly to a heap-based buffer overflow. Because this occurs at the heap layer, it results in the corruption of adjacent heap metadata or user-controlled application data structures.\nThe exploit impact depends on the specific memory layout and the state of the heap allocator at the time of execution. Memory corruption can be leveraged by an attacker to overwrite sensitive pointers, function pointers, or data objects. This may facilitate arbitrary code execution under the context of the process running the parser. In instances where code execution is not achievable, the resulting heap corruption will typically trigger a crash, causing a denial of service.\nExploitation requires no elevated privileges or prior authentication; it is essentially a drive-by attack where the target must simply parse an attacker-controlled XML file. The risk is constrained to 32-bit architectures, as 64-bit systems handle larger address spaces and integer constraints differently, rendering the specific overflow condition ineffective for the same calculation logic."
}