Logo
vulnerabilityCVE-2026-25210
Name
CVE-2026-25210
Source
NVD ( link)Debian ( link)
Description
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
expat
Patched

Vulnerability Ratings#


6.9
CVSSv31
7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.8.1
Not Affected
buildroot
master
2.8.1
Not Affected
openwrt
master
2.8.1-r1
Not Affected
openwrt
openwrt-25.12
2.8.1-r1
Not Affected
yocto
master
2.8.1
Not Affected
yocto
scarthgap
2.6.4
Patched

Resolved with patches#


expat (yocto:kirkstone)

#
Title
Author
Resolve
1
lib: Introduce an integer overflow check for tag buffer
Matthew Fernandez <matthew.fernandez@gmail.com>
CVE-2026-25210
2
lib: Realign a size with the `REALLOC` type signature it is
Matthew Fernandez <matthew.fernandez@gmail.com>
CVE-2026-25210
3
lib: Make a doubling more readable
Matthew Fernandez <matthew.fernandez@gmail.com>
CVE-2026-25210

expat (yocto:scarthgap)

#
Title
Author
Resolve
1
lib: Introduce an integer overflow check for tag buffer
Matthew Fernandez <matthew.fernandez@gmail.com>
CVE-2026-25210
2
lib: Realign a size with the `REALLOC` type signature it is
Matthew Fernandez <matthew.fernandez@gmail.com>
CVE-2026-25210
3
lib: Make a doubling more readable
Matthew Fernandez <matthew.fernandez@gmail.com>
CVE-2026-25210