First published: Mon Oct 24 2022(Updated: )
A use-after-free flaw was found in the Expat package, caused by destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations. This may lead to availability disruptions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/expat | <=2.2.6-2+deb10u4 | 2.2.6-2+deb10u6 2.2.10-2+deb11u5 2.5.0-1 2.5.0-2 |
debian/expat | <=2.2.10-2<=2.4.9-1 | 2.5.0-1 2.2.10-2+deb11u5 |
redhat/expat | <0:2.2.5-10.el8_7.1 | 0:2.2.5-10.el8_7.1 |
redhat/expat | <0:2.4.9-1.el9_1.1 | 0:2.4.9-1.el9_1.1 |
redhat/expat | <2.5.0 | 2.5.0 |
Android | ||
Debian (libexpat1) | <=2.4.9 | |
Debian | =10.0 | |
Debian | =11.0 | |
Fedora | =35 | |
Fedora | =36 | |
Fedora | =37 | |
All of | ||
netapp h300s firmware | ||
netapp h300s | ||
All of | ||
NetApp H500S Firmware | ||
netapp h500s | ||
All of | ||
netapp h700s firmware | ||
netapp h700s | ||
All of | ||
netapp h410s firmware | ||
netapp h410s | ||
All of | ||
netapp h410c firmware | ||
netapp h410c | ||
NetApp Active IQ Unified Manager for VMware vSphere | ||
NetApp OnCommand Workflow Automation | ||
netapp solidfire \& hci management node | ||
All of | ||
netapp hci compute node firmware | ||
netapp hci compute node | ||
NetApp Baseboard Management Controller Firmware | ||
netapp baseboard management controller h300s | ||
NetApp Baseboard Management Controller Firmware | ||
netapp baseboard management controller h500s | ||
NetApp Baseboard Management Controller Firmware | ||
netapp baseboard management controller h700s | ||
NetApp Baseboard Management Controller Firmware | ||
netapp baseboard management controller h410s | ||
netapp baseboard management controller h410c firmware | ||
netapp baseboard management controller h410c | ||
netapp hci compute node firmware | ||
netapp hci compute node | ||
IBM Data Virtualization on Cloud Pak for Data | <=3.0 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.2 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.1 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.0 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.8 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-43680 is a use-after-free vulnerability in the Expat package, specifically in the destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
CVE-2022-43680 has a severity level of 7.5 (high).
CVE-2022-43680 affects the expat package in various versions on Debian, Red Hat, Google Android, and other platforms.
To fix CVE-2022-43680, update the affected expat package to the recommended versions provided by the vendor.
More information about CVE-2022-43680 can be found in the references section of the vulnerability report.