CVE-2022-25313

medium
Published 2022-07-01 Β· Modified 2022-07-21
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

Moderate: expat security update

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description expat: Stack exhaustion in doctype parsing Red Hat statement This flaw affects applications that leverage expat to parse untrusted XML files. Applications which only parse trusted XML files or do not process XML files at all are not affected by this flaw. CVSS v3: 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat…

Description

expat: Stack exhaustion in doctype parsing

Red Hat statement

This flaw affects applications that leverage expat to parse untrusted XML files. Applications which only parse trusted XML files or do not process XML files at all are not affected by this flaw.

CVSS v3: 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8mingw-expat-0:2.4.8-1.el8RHSA-2022:78112022-11-08T00:00:00Z
Red Hat Enterprise Linux 8expat-0:2.2.5-8.el8_6.2RHSA-2022:53142022-06-30T00:00:00Z
Red Hat Enterprise Linux 8.2 Advanced Update Supportexpat-0:2.2.10-1.el8_2RHSA-2025:228712025-12-09T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportexpat-0:2.2.10-1.el8_4RHSA-2025:227852025-12-04T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onexpat-0:2.2.10-1.el8_4RHSA-2025:227852025-12-04T00:00:00Z
Red Hat Enterprise Linux 9expat-0:2.2.10-12.el9_0.2RHSA-2022:52442022-07-01T00:00:00Z
Red Hat Enterprise Linux 9expat-0:2.2.10-12.el9_0.2RHSA-2022:52442022-07-01T00:00:00Z
Text-Only JBCSexpatRHSA-2022:71442022-10-26T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6expatOut of support scope
Red Hat Enterprise Linux 7expatOut of support scope
Red Hat Enterprise Linux 7firefoxOut of support scope
Red Hat Enterprise Linux 7thunderbirdOut of support scope
Red Hat Enterprise Linux 8firefoxWill not fix
Red Hat Enterprise Linux 8firefox:flatpak/firefoxWill not fix
Red Hat Enterprise Linux 8thunderbirdWill not fix
Red Hat Enterprise Linux 8thunderbird:flatpak/thunderbirdWill not fix
Red Hat Enterprise Linux 8xmlrpc-cNot affected
Red Hat Enterprise Linux 9firefoxAffected
Red Hat Enterprise Linux 9thunderbirdAffected
Red Hat Enterprise Linux 9xmlrpc-cNot affected

Apply commands

bash fix
Apply RHSA-2022:7811 for Red Hat Enterprise Linux 8
yum update -y mingw-expat
# or:
dnf upgrade -y mingw-expat

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 9Affected
redhatRed Hat Enterprise Linux 9Affected
redhatRed Hat Enterprise Linux 9Not affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
9 Fixed expat-2.2.10-12.el9_0.2.aarch64.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.4.5-1
sid Fixed 2.4.5-1
forky Fixed 2.4.5-1
bullseye Fixed 2.2.10-2+deb11u2
bookworm Fixed 2.4.5-1
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.