The libexpat library is vulnerable to a stack overflow due to uncontrolled recursion when processing deeply nested XML entities. This can cause the application to crash, resulting in a denial of service (DoS) or potentially leading to memory corruption, depending on the user's environment and how the library is used. The issue is triggered by supplying a specially crafted XML document designed to create a long chain of recursive entities.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:3531 https://access.redhat.com/errata/RHSA-2025:3531
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:3913 https://access.redhat.com/errata/RHSA-2025:3913
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:4048 https://access.redhat.com/errata/RHSA-2025:4048
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:4447 https://access.redhat.com/errata/RHSA-2025:4447
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Via RHSA-2025:4448 https://access.redhat.com/errata/RHSA-2025:4448
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2025:4446 https://access.redhat.com/errata/RHSA-2025:4446
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:4449 https://access.redhat.com/errata/RHSA-2025:4449
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7444 https://access.redhat.com/errata/RHSA-2025:7444
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:7512 https://access.redhat.com/errata/RHSA-2025:7512