Expat 2.8.3 及之前版本存在一个越界读取漏洞,攻击者可通过处理由 XML_ExternalEntityParserCreate 创建的外部实体解析器中的 XML 文件,触发内存破坏。ELEMENT_TYPE 成员之间的结构体大小不匹配导致 storeAtts 函数在分配内存边界之外读取 attIndex 成员,进而引发非 CDATA 属性中空白字符无法正确归一化,或野指针解引用导致段错误(segfault)。该漏洞由 CVE-2026-66046 的修复引入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet