RHSA-2022:6833: Important: expat security update
Expat is a C library for parsing XML documents.Security Fix(es): expat: a use-after-free in the doContent function in xmlparse.c (CVE-2022-40674) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 2.2.5-3.el8_1.2 - Upgrade
Upgrade
redhat/expat-debuginfoto a version that resolves this vulnerability.Fixed in 2.2.5-3.el8_1.2 - Upgrade
Upgrade
redhat/expat-debugsourceto a version that resolves this vulnerability.Fixed in 2.2.5-3.el8_1.2 - Upgrade
Upgrade
redhat/expat-develto a version that resolves this vulnerability.Fixed in 2.2.5-3.el8_1.2 - Upgrade
Upgrade
expatto a version that resolves this vulnerability.Fixed in 2.2.5-3.el8_1.2 - Upgrade
Upgrade
expat-develto a version that resolves this vulnerability.Fixed in 2.2.5-3.el8_1.2 - Upgrade
Upgrade
expat-debuginfoto a version that resolves this vulnerability.Fixed in 2.2.5-3.el8_1.2 - Upgrade
Upgrade
expat-debugsourceto a version that resolves this vulnerability.Fixed in 2.2.5-3.el8_1.2
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:6833?
The severity of RHSA-2022:6833 is classified as important.
How do I fix RHSA-2022:6833?
To fix RHSA-2022:6833, update the expat package to version 2.2.5-3.el8_1.2 or later.
What is CVE-2022-40674 related to RHSA-2022:6833?
CVE-2022-40674 refers to a use-after-free vulnerability in the doContent function in xmlparse.c of the expat library.
Which systems are affected by RHSA-2022:6833?
RHSA-2022:6833 affects systems running certain versions of the expat package across multiple architectures including x86_64 and ppc64le.
What components are impacted by RHSA-2022:6833?
The components impacted by RHSA-2022:6833 include expat, expat-debuginfo, expat-debugsource, and expat-devel.