CVE-2022-22822: Integer Overflow
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Other sources
expat (libexpat) is susceptible to a software flaw that causes process interruption. When processing a large number of prefixed XML attributes on a single tag libexpat can terminate unexpectedly due to integer overflow. The highest threat from this vulnerability is to availability confidentiality and integrity.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-22822?
CVE-2022-22822 is a vulnerability in the Expat library (libexpat) before version 2.4.3 that allows an integer overflow, leading to process interruption.
What is the severity of CVE-2022-22822?
The severity of CVE-2022-22822 is critical with a CVSS score of 9.8.
What is the affected software for CVE-2022-22822?
The affected software includes Expat (libexpat) versions before 2.4.3, as well as other packages and distributions listed in the vulnerability description.
How can I fix CVE-2022-22822?
To fix CVE-2022-22822, it is recommended to update Expat (libexpat) to version 2.4.3 or apply the provided patches or remedies for the respective packages and distributions.
Where can I find more information about CVE-2022-22822?
You can find more information about CVE-2022-22822 in the provided references: [link1](https://github.com/libexpat/libexpat/pull/539), [link2](http://www.openwall.com/lists/oss-security/2022/01/17/3), [link3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2044458).