Impact
In libexpat 2.8.2 and 2.8.3 before 2.8.4, the library misinterprets the getentropy function’s return code, resulting in insufficient entropy during XML parsing. This weakness (CWE-331 and CWE-394) allows crafted XML content to trigger hash flooding, exhausting CPU resources and causing a denial of service.
Affected Systems
The vulnerability affects the libexpat project’s libexpat library in versions 2.8.2 and 2.8.3 that have not yet been upgraded to 2.8.4 or later. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium severity, and the EPSS score of < 1% suggests a very low but nonzero exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through an application that accepts XML input from an external source; by providing specially crafted XML, an attacker can trigger hash flooding and force the target to consume excessive computational resources, leading to service interruption.
OpenCVE Enrichment