CVE-2022-40674: Use After Free
A flaw in XML parsing could have led to a use-after-free causing a potentially exploitable crash.In official releases of Firefox this vulnerability is mitigated by wasm sandboxing; versions managed by Linux distributions may have other settings.
Other sources
A vulnerability was found in expat. With this flaw, it is possible to create a situation in which parsing is suspended while substituting in an internal entity so that XMLResumeParser directly uses the internalEntityProcessor as its processor. If the subsequent parse includes some unclosed tags, this will return without calling storeRawNames to ensure that the raw versions of the tag names are stored in memory other than the parse buffer itself. Issues occur if the parse buffer is changed or reallocated (for example, if processing a file line by line), problems occur. Using this vulnerability in the doContent function allows an attacker to triage a denial of service or potentially arbitrary code execution.
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
libexpat could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in the doContent function in xmlparse.c. An attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/expatto a version that resolves this vulnerability.Fixed in 2.2.6-2+deb10u6Fixed in 2.2.10-2+deb11u5Fixed in 2.5.0-1Fixed in 2.5.0-2 - Upgrade
Upgrade
debian/expatto a version that resolves this vulnerability.Fixed in 2.4.8-2Fixed in 2.2.10-2+deb11u4 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 0:2.0.1-15.el6_10 - Upgrade
Upgrade
redhat/compat-expat1to a version that resolves this vulnerability.Fixed in 0:1.95.8-9.el6_10 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 0:2.1.0-15.el7_9 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:102.3.0-7.el7_9 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:102.3.0-4.el7_9 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:102.3.0-4.el8_6 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:102.3.0-7.el8_6 - Upgrade
Upgrade
redhat/mingw-expatto a version that resolves this vulnerability.Fixed in 0:2.4.8-2.el8 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 0:2.2.5-8.el8_6.3 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:102.3.0-7.el8_1 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:102.3.0-4.el8_1 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 0:2.2.5-3.el8_1.2 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:102.3.0-4.el8_2 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:102.3.0-7.el8_2 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 0:2.2.5-3.el8_2.3 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:102.3.0-4.el8_4 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:102.3.0-7.el8_4 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 0:2.2.5-4.el8_4.4 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 0:2.2.10-12.el9_0.3 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:102.3.0-7.el9_0 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:102.3.0-4.el9_0 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 107 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 2.4.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.1.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.1.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.1.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.4.1 - Upgrade
Upgrade
libexpatto a version that resolves this vulnerability.Fixed in 2.4.9 - Compensating control
Restrict applications using the expat library from processing XML content (no known mitigation other than this restriction).
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2022:6921
- RHSA-2022:6967
- RHSA-2022:6834
- RHSA-2022:6997
- RHSA-2022:6998
- RHSA-2022:7023
- RHSA-2022:7024
- RHSA-2023:3068
- RHSA-2022:6878
- RHSA-2022:7019
- RHSA-2022:7021
- RHSA-2022:6833
- RHSA-2022:6996
- RHSA-2022:7022
- RHSA-2022:6832
- RHSA-2022:6995
- RHSA-2022:7025
- RHSA-2022:6831
- RHSA-2022:6838
- RHSA-2022:7020
- RHSA-2022:7026
- RHSA-2022:8841
- RHSA-2022:8598
- IBM-6999317
- MFSA2022-47
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-40674?
CVE-2022-40674 is a vulnerability in libexpat before 2.4.9 that allows for a use-after-free vulnerability in the doContent function in xmlparse.c.
What is the severity of CVE-2022-40674?
CVE-2022-40674 has a severity rating of 8.1 (high).
How does CVE-2022-40674 impact the affected software?
CVE-2022-40674 affects the expat package versions 2.4.8-2 and 2.2.10-2+deb11u4 in Debian, as well as other Red Hat packages such as thunderbird and firefox.
Is there a fix available for CVE-2022-40674?
Yes, there are fixes available for CVE-2022-40674. For Debian, updating to version 2.4.9 or higher of the expat package is recommended. Red Hat provides specific version updates for the affected packages.
Where can I find more information about CVE-2022-40674?
You can find more information about CVE-2022-40674 in the bugzilla.mozilla.org and mozilla.org security advisories, as well as in the GitHub pull request related to the vulnerability.