CVE-2022-40674: Use After Free

Published Sep 14, 2022
·
Updated

A flaw in XML parsing could have led to a use-after-free causing a potentially exploitable crash.In official releases of Firefox this vulnerability is mitigated by wasm sandboxing; versions managed by Linux distributions may have other settings.

Other sources

A vulnerability was found in expat. With this flaw, it is possible to create a situation in which parsing is suspended while substituting in an internal entity so that XMLResumeParser directly uses the internalEntityProcessor as its processor. If the subsequent parse includes some unclosed tags, this will return without calling storeRawNames to ensure that the raw versions of the tag names are stored in memory other than the parse buffer itself. Issues occur if the parse buffer is changed or reallocated (for example, if processing a file line by line), problems occur. Using this vulnerability in the doContent function allows an attacker to triage a denial of service or potentially arbitrary code execution.

libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

libexpat could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in the doContent function in xmlparse.c. An attacker could exploit this vulnerability to execute arbitrary code on the system.

IBM

Affected Software

51 affected componentsFixes available
debian/expat<=2.2.6-2+deb10u4
2.2.6-2+deb10u62.2.10-2+deb11u52.5.0-12.5.0-2
debian/expat<=2.2.10-2, <=2.2.10-2+deb11u3, <=2.4.8-1
2.4.8-22.2.10-2+deb11u4
redhat/expat<0:2.0.1-15.el6_10
0:2.0.1-15.el6_10
redhat/compat-expat1<0:1.95.8-9.el6_10
0:1.95.8-9.el6_10
redhat/expat<0:2.1.0-15.el7_9
0:2.1.0-15.el7_9
redhat/firefox<0:102.3.0-7.el7_9
0:102.3.0-7.el7_9
redhat/thunderbird<0:102.3.0-4.el7_9
0:102.3.0-4.el7_9
redhat/thunderbird<0:102.3.0-4.el8_6
0:102.3.0-4.el8_6
redhat/firefox<0:102.3.0-7.el8_6
0:102.3.0-7.el8_6
redhat/mingw-expat<0:2.4.8-2.el8
0:2.4.8-2.el8
redhat/expat<0:2.2.5-8.el8_6.3
0:2.2.5-8.el8_6.3
redhat/firefox<0:102.3.0-7.el8_1
0:102.3.0-7.el8_1
redhat/thunderbird<0:102.3.0-4.el8_1
0:102.3.0-4.el8_1
redhat/expat<0:2.2.5-3.el8_1.2
0:2.2.5-3.el8_1.2
redhat/thunderbird<0:102.3.0-4.el8_2
0:102.3.0-4.el8_2
redhat/firefox<0:102.3.0-7.el8_2
0:102.3.0-7.el8_2
redhat/expat<0:2.2.5-3.el8_2.3
0:2.2.5-3.el8_2.3
redhat/thunderbird<0:102.3.0-4.el8_4
0:102.3.0-4.el8_4
redhat/firefox<0:102.3.0-7.el8_4
0:102.3.0-7.el8_4
redhat/expat<0:2.2.5-4.el8_4.4
0:2.2.5-4.el8_4.4
redhat/expat<0:2.2.10-12.el9_0.3
0:2.2.10-12.el9_0.3
redhat/firefox<0:102.3.0-7.el9_0
0:102.3.0-7.el9_0
redhat/thunderbird<0:102.3.0-4.el9_0
0:102.3.0-4.el9_0
IBM BM Security Guardium<=11.3
IBM Security Guardium<=11.4
IBM Security Guardium<=11.5
Mozilla Firefox<107
107
Libexpat Project Libexpat<2.4.9
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Fedoraproject Fedora=37
redhat/expat<2.4.9
2.4.9
F5 BIG-IP>=17.0.0<=17.1.0
17.1.1
F5 BIG-IP>=16.1.0<=16.1.3
16.1.4
F5 BIG-IP>=15.1.0<=15.1.8
15.1.9
F5 BIG-IP>=14.1.0<=14.1.5
F5 BIG-IP>=13.1.0<=13.1.5
F5 BIG-IP (ASM)>=17.0.0<=17.1.1
F5 BIG-IP (ASM)>=16.1.0<=16.1.4
F5 BIG-IP (ASM)>=15.1.0<=15.1.10
F5 BIG-IP (ASM)>=14.1.0<=14.1.5
F5 BIG-IP (ASM)>=13.1.0<=13.1.5
F5 BIG-IP (DNS)>=17.0.0<=17.1.0
17.1.1
F5 BIG-IP (DNS)>=16.1.0<=16.1.3
16.1.4
F5 BIG-IP (DNS)>=15.1.0<=15.1.8
15.1.9
F5 BIG-IP (DNS)>=14.1.0<=14.1.5
F5 BIG-IP (DNS)>=13.1.0<=13.1.5
F5 BIG-IQ Centralized Management>=8.0.0<=8.4.0
8.4.1
F5 BIG-IQ Centralized Management=7.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/expat to a version that resolves this vulnerability.

    Fixed in 2.2.6-2+deb10u6Fixed in 2.2.10-2+deb11u5Fixed in 2.5.0-1Fixed in 2.5.0-2
  2. Upgrade

    Upgrade debian/expat to a version that resolves this vulnerability.

    Fixed in 2.4.8-2Fixed in 2.2.10-2+deb11u4
  3. Upgrade

    Upgrade redhat/expat to a version that resolves this vulnerability.

    Fixed in 0:2.0.1-15.el6_10
  4. Upgrade

    Upgrade redhat/compat-expat1 to a version that resolves this vulnerability.

    Fixed in 0:1.95.8-9.el6_10
  5. Upgrade

    Upgrade redhat/expat to a version that resolves this vulnerability.

    Fixed in 0:2.1.0-15.el7_9
  6. Upgrade

    Upgrade redhat/firefox to a version that resolves this vulnerability.

    Fixed in 0:102.3.0-7.el7_9
  7. Upgrade

    Upgrade redhat/thunderbird to a version that resolves this vulnerability.

    Fixed in 0:102.3.0-4.el7_9
  8. Upgrade

    Upgrade redhat/thunderbird to a version that resolves this vulnerability.

    Fixed in 0:102.3.0-4.el8_6
  9. Upgrade

    Upgrade redhat/firefox to a version that resolves this vulnerability.

    Fixed in 0:102.3.0-7.el8_6
  10. Upgrade

    Upgrade redhat/mingw-expat to a version that resolves this vulnerability.

    Fixed in 0:2.4.8-2.el8
  11. Upgrade

    Upgrade redhat/expat to a version that resolves this vulnerability.

    Fixed in 0:2.2.5-8.el8_6.3
  12. Upgrade

    Upgrade redhat/firefox to a version that resolves this vulnerability.

    Fixed in 0:102.3.0-7.el8_1
  13. Upgrade

    Upgrade redhat/thunderbird to a version that resolves this vulnerability.

    Fixed in 0:102.3.0-4.el8_1
  14. Upgrade

    Upgrade redhat/expat to a version that resolves this vulnerability.

    Fixed in 0:2.2.5-3.el8_1.2
  15. Upgrade

    Upgrade redhat/thunderbird to a version that resolves this vulnerability.

    Fixed in 0:102.3.0-4.el8_2
  16. Upgrade

    Upgrade redhat/firefox to a version that resolves this vulnerability.

    Fixed in 0:102.3.0-7.el8_2
  17. Upgrade

    Upgrade redhat/expat to a version that resolves this vulnerability.

    Fixed in 0:2.2.5-3.el8_2.3
  18. Upgrade

    Upgrade redhat/thunderbird to a version that resolves this vulnerability.

    Fixed in 0:102.3.0-4.el8_4
  19. Upgrade

    Upgrade redhat/firefox to a version that resolves this vulnerability.

    Fixed in 0:102.3.0-7.el8_4
  20. Upgrade

    Upgrade redhat/expat to a version that resolves this vulnerability.

    Fixed in 0:2.2.5-4.el8_4.4
  21. Upgrade

    Upgrade redhat/expat to a version that resolves this vulnerability.

    Fixed in 0:2.2.10-12.el9_0.3
  22. Upgrade

    Upgrade redhat/firefox to a version that resolves this vulnerability.

    Fixed in 0:102.3.0-7.el9_0
  23. Upgrade

    Upgrade redhat/thunderbird to a version that resolves this vulnerability.

    Fixed in 0:102.3.0-4.el9_0
  24. Upgrade

    Upgrade Firefox to a version that resolves this vulnerability.

    Fixed in 107
  25. Upgrade

    Upgrade redhat/expat to a version that resolves this vulnerability.

    Fixed in 2.4.9
  26. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 17.1.1
  27. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 16.1.4
  28. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 15.1.9
  29. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 8.4.1
  30. Upgrade

    Upgrade libexpat to a version that resolves this vulnerability.

    Fixed in 2.4.9
  31. Compensating control

    Restrict applications using the expat library from processing XML content (no known mitigation other than this restriction).

Event History

Sep 14, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 29, 2022
Data Sourced
via Red Hat·05:02 AM
DescriptionSeverityAffected Software
Oct 31, 2022
Advisory Published
via F5·10:05 AM
Data Sourced
via F5·10:05 AM
DescriptionSeverityWeaknessAffected Software
Nov 27, 58461
Event
via F5·03:28 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2022-40674?

CVE-2022-40674 is a vulnerability in libexpat before 2.4.9 that allows for a use-after-free vulnerability in the doContent function in xmlparse.c.

2

What is the severity of CVE-2022-40674?

CVE-2022-40674 has a severity rating of 8.1 (high).

3

How does CVE-2022-40674 impact the affected software?

CVE-2022-40674 affects the expat package versions 2.4.8-2 and 2.2.10-2+deb11u4 in Debian, as well as other Red Hat packages such as thunderbird and firefox.

4

Is there a fix available for CVE-2022-40674?

Yes, there are fixes available for CVE-2022-40674. For Debian, updating to version 2.4.9 or higher of the expat package is recommended. Red Hat provides specific version updates for the affected packages.

5

Where can I find more information about CVE-2022-40674?

You can find more information about CVE-2022-40674 in the bugzilla.mozilla.org and mozilla.org security advisories, as well as in the GitHub pull request related to the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203