expat: Stack exhaustion in doctype parsing
Published Feb 18, 2022
6.5
MEDIUMCVSS 3.1
EPSS 3.29%
Description
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
Affected products
No data.
Configuration 1
- < 2.4.5
Configuration 2
- 10.0
- 11.0
Configuration 3
- 34
- 35
Configuration 4
- 12.2.1.3.0
- 12.2.1.4.0
- 8.8
Configuration 5
- < 3.1
No data.
Red Hat Enterprise Linux 8
expat-0:2.2.5-8.el8_6.2
Fixed · RHSA-2022:5314
Red Hat Enterprise Linux 8
mingw-expat-0:2.4.8-1.el8
Fixed · RHSA-2022:7811
Red Hat Enterprise Linux 8.2 Advanced Update Support
expat-0:2.2.10-1.el8_2
Fixed · RHSA-2025:22871
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
expat-0:2.2.10-1.el8_4
Fixed · RHSA-2025:22785
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
expat-0:2.2.10-1.el8_4
Fixed · RHSA-2025:22785
Red Hat Enterprise Linux 9
expat-0:2.2.10-12.el9_0.2
Fixed · RHSA-2022:5244
Red Hat Enterprise Linux 9
expat-0:2.2.10-12.el9_0.2
Fixed · RHSA-2022:5244
Red Hat Enterprise Linux 6
expat
Out of support scope
Red Hat Enterprise Linux 7
expat
Out of support scope
Red Hat Enterprise Linux 7
firefox
Out of support scope
Red Hat Enterprise Linux 7
thunderbird
Out of support scope
Red Hat Enterprise Linux 8
firefox
Will not fix
Red Hat Enterprise Linux 8
firefox:flatpak/firefox
Will not fix
Red Hat Enterprise Linux 8
thunderbird
Will not fix
Red Hat Enterprise Linux 8
thunderbird:flatpak/thunderbird
Will not fix
Red Hat Enterprise Linux 8
xmlrpc-c
Not affected
Red Hat Enterprise Linux 9
firefox
Affected
Red Hat Enterprise Linux 9
thunderbird
Affected
Red Hat Enterprise Linux 9
xmlrpc-c
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | expat-0:2.2.5-8.el8_6.2 | Fixed | RHSA-2022:5314 |
| Red Hat Enterprise Linux 8 | mingw-expat-0:2.4.8-1.el8 | Fixed | RHSA-2022:7811 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | expat-0:2.2.10-1.el8_2 | Fixed | RHSA-2025:22871 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | expat-0:2.2.10-1.el8_4 | Fixed | RHSA-2025:22785 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | expat-0:2.2.10-1.el8_4 | Fixed | RHSA-2025:22785 |
| Red Hat Enterprise Linux 9 | expat-0:2.2.10-12.el9_0.2 | Fixed | RHSA-2022:5244 |
| Red Hat Enterprise Linux 9 | expat-0:2.2.10-12.el9_0.2 | Fixed | RHSA-2022:5244 |
| Red Hat Enterprise Linux 6 | expat | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | expat | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | thunderbird | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | firefox | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | firefox:flatpak/firefox | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | thunderbird | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | thunderbird:flatpak/thunderbird | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | xmlrpc-c | Not affected | n/a |
| Red Hat Enterprise Linux 9 | firefox | Affected | n/a |
| Red Hat Enterprise Linux 9 | thunderbird | Affected | n/a |
| Red Hat Enterprise Linux 9 | xmlrpc-c | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw affects applications that leverage expat to parse untrusted XML files. Applications which only parse trusted XML files or do not process XML files at all are not affected by this flaw.
Red Hat mitigation
There is no known mitigation other than restricting applications using the expat library from processing untrusted XML content.
References (16)
- http://www.openwall.com/lists/oss-security/2022/02/19/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-25313 Vendor Advisory
- https://blog.hartwork.org/posts/expat-2-4-5-released/
- https://bugzilla.redhat.com/show_bug.cgi?id=2056350 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf x_refsource_CONFIRMThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-29996 Advisory
- https://github.com/libexpat/libexpat/pull/558 x_refsource_MISCThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2022-25313
- https://security.gentoo.org/glsa/202209-24 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20220303-0008/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-25313
- https://www.debian.org/security/2022/dsa-5085 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data