First published: Mon Oct 24 2022(Updated: )
A use-after-free flaw was found in the Expat package, caused by destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations. This may lead to availability disruptions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/expat | <=2.2.6-2+deb10u4 | 2.2.6-2+deb10u6 2.2.10-2+deb11u5 2.5.0-1 2.5.0-2 |
debian/expat | <=2.2.10-2<=2.4.9-1 | 2.5.0-1 2.2.10-2+deb11u5 |
redhat/expat | <0:2.2.5-10.el8_7.1 | 0:2.2.5-10.el8_7.1 |
redhat/expat | <0:2.4.9-1.el9_1.1 | 0:2.4.9-1.el9_1.1 |
redhat/expat | <2.5.0 | 2.5.0 |
IBM Data Virtualization on Cloud Pak for Data | <=3.0 | |
IBM Watson Query with Cloud Pak for Data | <=2.2 | |
IBM Watson Query with Cloud Pak for Data | <=2.1 | |
IBM Watson Query with Cloud Pak for Data | <=2.0 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.8 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.7 | |
Android | ||
Libexpat | <=2.4.9 | |
Debian Linux | =10.0 | |
Debian Linux | =11.0 | |
Red Hat Fedora | =35 | |
Red Hat Fedora | =36 | |
Red Hat Fedora | =37 | |
All of | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
All of | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
All of | ||
NetApp H700S | ||
NetApp H700S | ||
All of | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
All of | ||
NetApp H410C | ||
NetApp H410C Firmware | ||
NetApp Active IQ Unified Manager for VMware vSphere | ||
NetApp OnCommand Workflow Automation | ||
NetApp SolidFire & HCI Management Node | ||
All of | ||
NetApp HCI Compute Node Firmware | ||
NetApp HCI Compute Node | ||
NetApp Baseboard Management Controller Firmware | ||
NetApp Baseboard Management Controller H300S | ||
NetApp Baseboard Management Controller Firmware | ||
NetApp Baseboard Management Controller H500S | ||
NetApp Baseboard Management Controller Firmware | ||
NetApp Baseboard Management Controller H700S | ||
NetApp Baseboard Management Controller Firmware | ||
NetApp Baseboard Management Controller H410S | ||
NetApp Baseboard Management Controller H410C | ||
NetApp Baseboard Management Controller H410C Firmware | ||
NetApp HCI Compute Node Firmware | ||
NetApp HCI Compute Node |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-43680 is a use-after-free vulnerability in the Expat package, specifically in the destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
CVE-2022-43680 has a severity level of 7.5 (high).
CVE-2022-43680 affects the expat package in various versions on Debian, Red Hat, Google Android, and other platforms.
To fix CVE-2022-43680, update the affected expat package to the recommended versions provided by the vendor.
More information about CVE-2022-43680 can be found in the references section of the vulnerability report.