Resource exhaustion in expat - CVE-2025-59375

 

Resource exhaustion in expat - CVE-2025-59375

Published: September 17, 2025


Vulnerability identifier: #VU115751
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-59375
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger large dynamic memory allocations via a small document and perform a denial of service (DoS) attack.


Affected software

expat
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP3
SUSE Manager Proxy 4.3
SUSE Linux Enterprise Server 15 SP5
SUSE Manager Retail Branch Server 4.3
SUSE Manager Server 4.3
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP4
Debian Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Workstation Extension 15
visionOS
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
OpenBSD
Red Hat CodeReady Linux Builder for x86_64
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
watchOS
macOS
Ubuntu
Basesystem Module
Desktop Applications Module
SUSE Package Hub 15
openSUSE Leap
tvOS
Apple iOS
iPadOS
openEuler
Fedora
Netezza Appliance
Financial Transaction Manager for RedHat OpenShift
DataStage on Cloud Pak for Data
IBM Enterprise Content Management Text Search
Maximo Application Suite - Monitor Component
CICS Transaction Gateway for Multiplatforms
DevOps Code ClearCase
IBM OpenPages with Watson
IBM Observability with Instana
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Advanced Cluster Security for Kubernetes
IBM Sterling Connect:Direct Web Services
Oracle Communications Unified Inventory Management
Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition
Oracle Financial Services Behavior Detection Platform
WebSphere Remote Server
IBM Rational ClearCase
IBM Rational ClearQuest
Tenable Nessus
App Connect Enterprise Certified Container
Oracle HTTP Server
IBM Business Automation Workflow
Oracle Communications Network Analytics Data Director
AppDynamics NodeJS Agent
AI Inference Server
AI Inference Server Model Optimization Tools
IBM Power Hardware Management Console (HMC)
Quay
Red Hat OpenShift Serverless
OpenShift Virtualization
Nessus Network Monitor
Red Hat OpenShift Container Platform
Communications Unified Assurance
LANTIME Operating System Firmware (LTOS)
IBM Qradar SIEM
Oracle Outside In Technology
Encryption Admin Utilities
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
expat (Ubuntu package)
expat
expat-debuginfo
expat-debugsource
expat-devel
expat-help
expat (Red Hat package)
mingw32-expat
mingw64-expat
mingw-expat (Red Hat package)
expat-doc
expat-static
libexpat-devel
libexpat1
libexpat1-debuginfo
libexpat1-32bit
libexpat1-debuginfo-32bit
expat-debuginfo-32bit
libexpat1-32bit-debuginfo
expat-32bit-debuginfo
libexpat1-64bit
libexpat-devel-32bit
libexpat-devel-64bit
expat-64bit-debuginfo
libexpat1-64bit-debuginfo
mingw-expat
expat (Debian package)
mingw32-fontconfig
mingw64-fontconfig
mingw-fontconfig (Red Hat package)
spice-client-win (Red Hat package)
firefox-esr (Debian package)
thunderbird (Debian package)
firefox-debuginfo
firefox-debugsource
firefox
MozillaFirefox-devel
MozillaFirefox-debugsource
MozillaFirefox-translations-common
MozillaFirefox-debuginfo
MozillaFirefox
MozillaThunderbird-debuginfo
MozillaThunderbird-translations-common
MozillaThunderbird
MozillaThunderbird-translations-other
MozillaThunderbird-debugsource
MozillaFirefox-translations-other
MozillaFirefox-branding-upstream
thunderbird
thunderbird-debuginfo
thunderbird-debugsource
thunderbird-librnp-rnp
thunderbird-wayland
Mozilla Thunderbird
OpenShift distributed tracing platform (Tempo)
IBM HTTP Server
IBM CICS TX Standard
Juniper Junos Space

How to mitigate CVE-2025-59375

Install updates from vendor's website.

expat - update to 2.7.2
Netezza Appliance - update to 1.0.0.1
visionOS - update to 26.3
IBM Observability with Instana - update to 1.0.311
Quay - update to 3.16.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.7.9, 4.8.7
DataStage on Cloud Pak for Data - addressed in versions 5.3.1 patch 9, 5.4.0.0 patch 4
IBM Enterprise Content Management Text Search - addressed in versions 5.5.12.0 IF007, 5.6.0.0 IF007, 5.7.0.0 IF004
Nessus Network Monitor - update to 6.5.3
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.16, 6.4.0.5
LANTIME Operating System Firmware (LTOS) - update to 7.10.004
IBM Qradar SIEM - update to 7.5.0 Update Pack 14 IF03
Maximo Application Suite - Monitor Component - addressed in versions 9.0.25, 9.1.15, 9.2.4
Tenable Nessus - addressed in versions 10.8.0, 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5, 10.8.6, 10.9.6, 10.11.1
watchOS - update to 26.3 23S620
App Connect Enterprise Certified Container - update to 12.19.0
macOS - addressed in versions 14.8.4 23J319, 15.7.4 24G517, 26.3 25D125
tvOS - update to 26.3 23K620
Apple iOS - addressed in versions 18.7.5 22H311, 26.3 23D127
iPadOS - addressed in versions 18.7.5 22H311, 26.3 23D127
AppDynamics NodeJS Agent - update to 25.12.1
Mozilla Thunderbird - addressed in versions 140.9.0, 149.0
Red Hat OpenShift Serverless - update to 1
expat (Ubuntu package) - addressed in versions 2.1.0-4ubuntu1.4+esm11, 2.1.0-4ubuntu1.4+esm12, 2.1.0-7ubuntu0.16.04.5+esm11, 2.1.0-7ubuntu0.16.04.5+esm13, 2.2.5-3ubuntu0.9+esm3, 2.2.5-3ubuntu0.9+esm4, 2.2.9-1ubuntu0.8+esm1, 2.2.9-1ubuntu0.8+esm2, 2.4.7-1ubuntu0.7, 2.4.7-1ubuntu0.8, 2.6.1-2ubuntu0.5, 2.7.1-2ubuntu0.2, 2.7.4-1ubuntu0.1
expat - addressed in versions 2.2.9-17, 2.4.1-18, 2.5.0-10, 2.5.0-11
expat-debuginfo - addressed in versions 2.2.9-17, 2.4.1-18, 2.5.0-10, 2.5.0-11
expat-debugsource - addressed in versions 2.2.9-17, 2.4.1-18, 2.5.0-10, 2.5.0-11
expat-devel - addressed in versions 2.2.9-17, 2.4.1-18, 2.5.0-10, 2.5.0-11
expat-help - addressed in versions 2.2.9-17, 2.4.1-18, 2.5.0-10, 2.5.0-11
expat (Red Hat package) - addressed in versions 2.2.10-1.el8_4, 2.2.10-1.el8_6, 2.2.10-1.el8_8, 2.2.10-12.el9_0.4, 2.5.0-1.el8_10, 2.5.0-1.el9_2.3, 2.5.0-5.el9_6.1, 2.5.0-5.el9_7.1, 2.7.1-1.el10_0.3, 2.7.1-1.el10_1.3
expat - addressed in versions 2.5.0-1, 2.5.0-8
expat-devel - addressed in versions 2.5.0-1, 2.5.0-8
mingw32-expat - update to 2.5.0-1
mingw64-expat - update to 2.5.0-1
mingw-expat (Red Hat package) - update to 2.5.0-1.el8_10
expat-doc - update to 2.5.0-8
expat-static - update to 2.5.0-8
expat-debuginfo - addressed in versions 2.7.1-21.46.1, 2.7.1-150000.3.39.1, 2.7.1-150400.3.31.1, 2.7.1-150700.3.6.1
libexpat-devel - addressed in versions 2.7.1-21.46.1, 2.7.1-150000.3.39.1, 2.7.1-150400.3.31.1, 2.7.1-150700.3.6.1
expat-debugsource - addressed in versions 2.7.1-21.46.1, 2.7.1-150000.3.39.1, 2.7.1-150400.3.31.1, 2.7.1-150700.3.6.1
libexpat1 - addressed in versions 2.7.1-21.46.1, 2.7.1-150000.3.39.1, 2.7.1-150400.3.31.1, 2.7.1-150700.3.6.1
expat - addressed in versions 2.7.1-21.46.1, 2.7.1-150000.3.39.1, 2.7.1-150400.3.31.1, 2.7.1-150700.3.6.1
libexpat1-debuginfo - addressed in versions 2.7.1-21.46.1, 2.7.1-150000.3.39.1, 2.7.1-150400.3.31.1, 2.7.1-150700.3.6.1
libexpat1-32bit - addressed in versions 2.7.1-21.46.1, 2.7.1-150000.3.39.1, 2.7.1-150400.3.31.1, 2.7.1-150700.3.6.1
libexpat1-debuginfo-32bit - update to 2.7.1-21.46.1
expat-debuginfo-32bit - update to 2.7.1-21.46.1
libexpat1-32bit-debuginfo - addressed in versions 2.7.1-150000.3.39.1, 2.7.1-150400.3.31.1, 2.7.1-150700.3.6.1
expat-32bit-debuginfo - addressed in versions 2.7.1-150000.3.39.1, 2.7.1-150400.3.31.1, 2.7.1-150700.3.6.1
libexpat1-64bit - update to 2.7.1-150400.3.31.1
libexpat-devel-32bit - update to 2.7.1-150400.3.31.1
libexpat-devel-64bit - update to 2.7.1-150400.3.31.1
expat-64bit-debuginfo - update to 2.7.1-150400.3.31.1
libexpat1-64bit-debuginfo - update to 2.7.1-150400.3.31.1
expat - addressed in versions 2.7.2-1.fc41, 2.7.2-1.fc42
mingw-expat - addressed in versions 2.7.2-1.fc41, 2.7.2-1.fc42, 2.7.2-1.fc43
expat (Debian package) - update to 2.8.2-1~deb13u1
mingw32-fontconfig - update to 2.12.6-4
mingw64-fontconfig - update to 2.12.6-4
mingw-fontconfig (Red Hat package) - update to 2.12.6-4.el8_10
AI Inference Server - update to 3.2.5
AI Inference Server Model Optimization Tools - update to 3.2.5
OpenShift distributed tracing platform (Tempo) - update to 3.8.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.84, 4.13.63, 4.14.61, 4.15.61, 4.16.55, 4.17.47, 4.18.31, 4.19.22, 4.20.10
OpenShift Virtualization - update to 4.19.17
IBM HTTP Server - addressed in versions 8.5.5.29, 9.0.5.27
spice-client-win (Red Hat package) - addressed in versions 8.10-3.el8_2.1, 8.10-3.el8_4.1, 8.10-3.el8_6.1, 8.10-3.el8_8.1
IBM OpenPages with Watson - update to 9.0.5.26
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1063.2, 11.1.1111.5
IBM CICS TX Standard - update to 11.1.0.0 ifix40
Encryption Admin Utilities - update to 11.13.1
Juniper Junos Space - update to 26.1R1 Patch V1
firefox-esr (Debian package) - addressed in versions 140.9.0esr-1~deb12u1, 140.9.0esr-1~deb13u1
thunderbird (Debian package) - addressed in versions 1:140.9.0esr-1~deb12u1, 1:140.9.0esr-1~deb13u1
firefox-debuginfo - update to 140.9.0-1
firefox-debugsource - update to 140.9.0-1
firefox - update to 140.9.0-1
MozillaFirefox-devel - addressed in versions 140.9.0-112.304.2, 140.9.0-150200.152.225.1
MozillaFirefox-debugsource - addressed in versions 140.9.0-112.304.2, 140.9.0-150200.152.225.1
MozillaFirefox-translations-common - addressed in versions 140.9.0-112.304.2, 140.9.0-150200.152.225.1
MozillaFirefox-debuginfo - addressed in versions 140.9.0-112.304.2, 140.9.0-150200.152.225.1
MozillaFirefox - addressed in versions 140.9.0-112.304.2, 140.9.0-150200.152.225.1
MozillaThunderbird-debuginfo - update to 140.9.0-150200.8.263.1
MozillaThunderbird-translations-common - update to 140.9.0-150200.8.263.1
MozillaThunderbird - update to 140.9.0-150200.8.263.1
MozillaThunderbird-translations-other - update to 140.9.0-150200.8.263.1
MozillaThunderbird-debugsource - update to 140.9.0-150200.8.263.1
MozillaFirefox-translations-other - update to 140.9.0-150200.152.225.1
MozillaFirefox-branding-upstream - update to 140.9.0-150200.152.225.1
thunderbird - update to 140.9.1-1
thunderbird-debuginfo - update to 140.9.1-1
thunderbird-debugsource - update to 140.9.1-1
thunderbird-librnp-rnp - update to 140.9.1-1
thunderbird-wayland - update to 140.9.1-1

External References

Related Security Bulletins