PT-2026-102606 · Pypy · Pypy
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PyPy versions prior to 3.11.16
PyPy versions prior to 3.12.14
Description
A use-after-free issue exists in the
pyexpat module's ExternalEntityParserCreate() function. This occurs when applications create external-entity sub-parsers without maintaining a reference to the parent parser. The child parser keeps a raw C back-pointer to the parent parser struct, but the tracing garbage collector may free the parent's C struct. Consequently, the bundled libexpat dereferences this freed pointer during token parsing, leading to memory corruption via a specially crafted XML document.Recommendations
Update to version 3.11.16 or later.
Update to version 3.12.14 or later.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pypy