CVE-2022-22826: Integer Overflow
expat (libexpat) is susceptible to a software flaw that causes process interruption. When processing a large number of prefixed XML attributes on a single tag can libexpat can terminate unexpectedly due to integer overflow. The highest threat from this vulnerability is to availability, confidentiality and integrity.
Other sources
Expat could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow of nextScaffoldPart in xmlparse.c. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-22826.
What is the severity of CVE-2022-22826?
The severity of CVE-2022-22826 is high (8.8).
What is the affected software?
The affected software includes Expat (libexpat) versions before 2.4.3, and some specific versions of Red Hat, Ubuntu, Debian, Firefox, libxmltok, Thunderbird, Nessus, and Siemens SINEMA Remote Connect Server.
How can the vulnerability be exploited?
The vulnerability can be exploited when processing a large number of prefixed XML attributes on a single tag, which can lead to unexpected termination due to integer overflow.
How do I fix CVE-2022-22826?
To fix CVE-2022-22826, update Expat (libexpat) to version 2.4.3 or apply the appropriate remedy for the specific affected software versions.