RHSA-2022:1012: Important: expat security update
Expat is a C library for parsing XML documents.Security Fix(es): expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution (CVE-2022-25235) expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution (CVE-2022-25236) expat: Integer overflow in storeRawNames() (CVE-2022-25315) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 2.2.5-4.el8_4.2 - Upgrade
Upgrade
redhat/expat-debuginfoto a version that resolves this vulnerability.Fixed in 2.2.5-4.el8_4.2 - Upgrade
Upgrade
redhat/expat-debugsourceto a version that resolves this vulnerability.Fixed in 2.2.5-4.el8_4.2 - Upgrade
Upgrade
redhat/expat-develto a version that resolves this vulnerability.Fixed in 2.2.5-4.el8_4.2 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 2.2.5-4.el8_4.2.aa - Upgrade
Upgrade
redhat/expat-debuginfoto a version that resolves this vulnerability.Fixed in 2.2.5-4.el8_4.2.aa - Upgrade
Upgrade
redhat/expat-debugsourceto a version that resolves this vulnerability.Fixed in 2.2.5-4.el8_4.2.aa - Upgrade
Upgrade
redhat/expat-develto a version that resolves this vulnerability.Fixed in 2.2.5-4.el8_4.2.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:1012?
The severity of RHSA-2022:1012 is classified as critical due to the potential for arbitrary code execution.
How do I fix RHSA-2022:1012?
To fix RHSA-2022:1012, update the expat package to version 2.2.5-4.el8_4.2.
What vulnerabilities does RHSA-2022:1012 address?
RHSA-2022:1012 addresses vulnerabilities including CVE-2022-25235 which allows for arbitrary code execution from malformed UTF-8 sequences.
Which software is affected by RHSA-2022:1012?
RHSA-2022:1012 affects the expat library across various packages such as expat, expat-devel, and expat-debuginfo.
Is there a specific version to upgrade for RHSA-2022:1012?
Yes, you should upgrade to version 2.2.5-4.el8_4.2 to mitigate the vulnerabilities addressed in RHSA-2022:1012.