VDB

GCVE-110-MAGEIA-2025-240

GCVE-110-MAGEIA-2025-240
Advisory Published
Vulnetix · Advisory published October 18, 2025
Improper restriction of xml entity expansion depth in libexpat. (CVE-2024-8176) This is an extension of the fix published in MGASA-2025-0109 that was determined by upstream to be incomplete. Libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing. (CVE-2025-59375)

Affected Products

VendorProductVersionsPlatforms
Mageiaexpat0 (affected), 2.7.3-1.mga9 (unaffected)

Browse GCVE Records

74,366 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›