AZL-105048

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105048.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105048
Upstream
Published
2026-09-29T17:17:06Z
Modified
2026-09-30T14:19:38Z
Summary
CVE-2026-102633 affecting package expat 2.8.3-2
Details

libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service.

References

Affected packages

Azure Linux:3 / expat

Package

Name
expat
Purl
pkg:rpm/azure-linux/expat

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.8.3-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105048.json"