CVE-2022-25315: Integer Overflow
An integer overflow was found in expat. The issue occurs in storeRawNames() by abusing the mbuffer expansion logic to allow allocations very close to INTMAX and out-of-bounds heap writes. This flaw can cause a denial of service or potentially arbitrary code execution.
Other sources
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 0:2.0.1-14.el6_10 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:91.7.0-3.el7_9 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:91.7.0-2.el7_9 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 0:2.1.0-14.el7_9 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:91.7.0-3.el8_5 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:91.7.0-2.el8_5 - Upgrade
Upgrade
redhat/mingw-expatto a version that resolves this vulnerability.Fixed in 0:2.4.8-1.el8 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 0:2.2.5-4.el8_5.3 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:91.7.0-3.el8_1 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:91.7.0-2.el8_1 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 0:2.2.5-3.el8_1.1 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:91.7.0-3.el8_2 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:91.7.0-2.el8_2 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 0:2.2.5-3.el8_2.2 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:91.7.0-3.el8_4 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:91.7.0-2.el8_4 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 0:2.2.5-4.el8_4.2 - Upgrade
Upgrade
redhat/redhat-virtualization-hostto a version that resolves this vulnerability.Fixed in 0:4.3.22-20220330.1.el7_9 - Upgrade
Upgrade
debian/expatto a version that resolves this vulnerability.Fixed in 2.2.6-2+deb10u4Fixed in 2.2.6-2+deb10u6Fixed in 2.2.10-2+deb11u5Fixed in 2.5.0-1Fixed in 2.5.0-2 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 2.4.5 - Upgrade
Upgrade
Expat (libexpat)to a version that resolves this vulnerability.Fixed in 2.4.5 - Compensating control
Restrict applications using the expat (libexpat) library from processing untrusted XML content, since there is no known mitigation for the integer overflow other than this restriction.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-25315?
CVE-2022-25315 is a vulnerability in Expat (aka libexpat) before version 2.4.5, which allows for an integer overflow in storeRawNames.
What is the severity of CVE-2022-25315?
The severity of CVE-2022-25315 is critical with a CVSS score of 9.8.
How does CVE-2022-25315 occur?
CVE-2022-25315 occurs in Expat through the function storeRawNames(), by abusing the m_buffer expansion logic to allow allocations very close to INT_MAX and out-of-bounds heap writes.
What are the affected software versions of CVE-2022-25315?
The affected software versions of CVE-2022-25315 include Expat 2.4.5 and earlier, as well as various versions of Firefox and Thunderbird.
How can CVE-2022-25315 be fixed?
To fix CVE-2022-25315, it is recommended to update to Expat version 2.4.5 or apply the appropriate patches provided by the software vendors.