Executive brief
libexpat is a widely used library for processing XML data in various software applications. A flaw in how it handles paused data processing could allow an attacker to cause a system crash or potentially execute unauthorized code. This occurs when the library fails to properly track its internal state during complex data handling tasks, leading to memory corruption.
Technical details
A use-after-free vulnerability exists in libexpat due to missing reentrancy guards in the XML_ResumeParser function. While other functions like XML_Parse and XML_GetBuffer were previously patched to track handler call depth, XML_ResumeParser was omitted. An attacker can exploit this by triggering a sequence where a handler suspends the parser and then immediately calls XML_ResumeParser, causing the parser to re-enter an active state while the outer parse is still on the stack. This leads to memory corruption and potential arbitrary code execution. The issue is addressed in version 2.8.2 by adding the isCalledFromInsideHandler check to XML_ResumeParser.
Affected products
- libexpat project libexpat before 2.8.2
Timeline
- 2026-06-06: other: Pull request submitted to libexpat repository
- 2026-06-19: disclosed: CVE published to NVD
- 2026-06-20: patched: Fix merged into master branch