Red Hat and Debian issued fixes for two vulnerabilities in the Expat XML parsing library: CVE-2018-20843 and CVE-2019-15903. CVE-2018-20843 affects Expat versions before 2.2.7; XML names containing excessive colon characters can drive high CPU and memory consumption, potentially causing an application to be killed by the operating system’s out-of-memory handler. Fuzzing demonstrated that a small malformed XML file could consume more than 2 GB of memory in Expat-based processing.
CVE-2019-15903, affecting versions before 2.2.8, allows crafted XML to force a premature transition from DTD to document parsing and can produce a heap-based buffer over-read when applications call XML_GetCurrentLineNumber or XML_GetCurrentColumnNumber. Red Hat released updates for affected RHEL 7 and RHEL 8 Expat packages, as well as JBoss Core Services components; administrators should install the applicable updates and restart all applications that load Expat for the remediations to take effect.

See affected versions and whether adversaries are exploiting it.
14 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2020:4484 for RHEL 8, providing Expat 2.2.5-4.el8 packages to fix CVE-2018-20843 and CVE-2019-15903.
Red Hat issued Moderate-severity advisory RHSA-2020:3952 for RHEL 7, providing Expat 2.1.0-12.el7 packages that fix CVE-2018-20843 and CVE-2019-15903.
RHSA-2020:2644 remediated CVE-2018-20843 and CVE-2019-15903 in affected JBoss Core Services HTTPD 2.4 components on RHEL 6 and RHEL 7.
Salvatore Bonaccorso reported Debian security bug #931031 for CVE-2018-20843, affecting Expat versions before 2.2.7. XML names with many colons could drive excessive CPU and RAM use, enabling denial of service.
Caolan McMahon opened libexpat issue #186 reporting that a malformed XML testcase caused xmlwf to consume more than 2 GB of memory before returning a parse error. LibreOffice, which uses Expat, exhibited the same behavior.
OSS-Fuzz filed issue #5226 after LibreOffice's mmlfuzzer repeatedly exceeded its 2 GB AddressSanitizer memory limit. The issue was later linked to a generic Expat parsing problem reproducible with xmlwf.
Red Hat issued RHSA-2025:22871 for RHEL 8.2 Advanced Update Support, recording remediation for CVE-2018-20843 and CVE-2019-15903.
Red Hat stated that no mitigation for CVE-2019-15903 met its criteria for usability, broad applicability, and stability.
The libexpat project fixed the heap-based buffer over-read in commit c20b758c332d9a13afbbb276d30db1d183a85d43; the issue was tracked upstream in issues 317 and 342 and pull request 318.
CVE-2019-15903 was identified in libexpat versions before 2.2.8. Crafted XML can prematurely move parsing from DTD to document mode, allowing line- or column-number calls to read past a heap buffer.
The upstream Expat project fixed the resource-exhaustion issue tracked as GitHub issue #186 in commit 11f8838bf99ea0a6f0b76f9760c43704d00c4ff6.
Debian fixed CVE-2018-20843 in expat 2.2.6-2 for unstable and 2.2.0-2+deb9u2 for stretch-security, correcting namespace-prefix extraction from XML names.
OSS-Fuzz closed issue #5226 as Won't Fix/Obsolete because the out-of-memory condition was considered unreproducible, and said it would stop filing similarly unreproducible OOM and timeout bugs.
OSS-Fuzz publicly opened the LibreOffice out-of-memory issue after its initial 90-day coordinated-disclosure deadline passed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
9 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugs.debian.org
Open sourcegithub.com
Open sourcebugs.chromium.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.