An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINTMAX equals SIZEMAX).
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-48454.json"