libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed. References: [1] https://github.com/libexpat/libexpat/pull/789 [2] https://github.com/libexpat/libexpat/commit/34b598c5f594b015c513c73f06e7ced3323edbf1
Created expat tracking bugs for this issue: Affects: fedora-all [bug 2262882] Created mingw-expat tracking bugs for this issue: Affects: fedora-all [bug 2262883] Created xmlrpc-c tracking bugs for this issue: Affects: fedora-all [bug 2262884]
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:1530 https://access.redhat.com/errata/RHSA-2024:1530
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:1615 https://access.redhat.com/errata/RHSA-2024:1615
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2024:2575 https://access.redhat.com/errata/RHSA-2024:2575
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2024:2839 https://access.redhat.com/errata/RHSA-2024:2839
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2024:3926 https://access.redhat.com/errata/RHSA-2024:3926
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:4259 https://access.redhat.com/errata/RHSA-2024:4259