CVE-2022-22822
published 2022-01-10CVE-2022-22822: addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.83%
91.0th percentile
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | expat | < expat 2.4.3-1 (bookworm) | expat 2.4.3-1 (bookworm) |
| debian | libxmltok | < expat 2.4.3-1 (bookworm) | expat 2.4.3-1 (bookworm) |
| android | — | — | |
| libexpat_project | libexpat | < 2.4.3 | 2.4.3 |
| msrc | cbl2_expat_2.4.3-1_on_cbl_mariner_2.0 | — | — |
| paloalto | pan-os | — | — |
| platform | external_expat | >= 10:0 < 10:2022-09-01 | 10:2022-09-01 |
| platform | external_expat | >= 11:0 < 11:2022-09-01 | 11:2022-09-01 |
| platform | external_expat | >= 12:0 < 12:2022-09-01 | 12:2022-09-01 |
| platform | external_expat | >= 12L:0 < 12L:2022-09-01 | 12L:2022-09-01 |
| siemens | sinema_remote_connect_server | < 3.1 | 3.1 |
| tenable | nessus | < 8.15.3 | 8.15.3 |
| tenable | nessus | >= 10.0.0 < 10.1.1 | 10.1.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libxmltok vulnerabilities
osv·2025-01-13·CVSS 6.8
CVE-2015-1283 [MEDIUM] libxmltok vulnerabilities
libxmltok vulnerabilities
It was discovered that Expat, contained within the xmltok library,
incorrectly handled malformed XML data. If a user or application were
tricked into opening a crafted XML file, an attacker could cause a denial
of service, or possibly execute arbitrary code. (CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2019-15903)
It was discovered that Expat, contained within the xmltok library,
incorrectly handled XML data containing a large number of colons, which
could lead to excessive resource consumption. If a user or application
were tricked into opening a crafted XML file, an attacker could possibly
use this issue to cause a denial of service. (CVE-2018-20843)
It was discovered that Expat, contained within the xmltok library,
incorrectly handled certain input, whi
OSV
CVE-2022-22822: In storeAtts of xmlparse
osv·2022-09-01
CVE-2022-22822 CVE-2022-22822: In storeAtts of xmlparse
In storeAtts of xmlparse.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
libxmltok vulnerabilities
osv·2022-07-19·CVSS 5.0
CVE-2012-1148 [MEDIUM] libxmltok vulnerabilities
libxmltok vulnerabilities
Tim Boddy, Gustavo Grieco and others discovered that Expat, that is
integrated in xmltok library, incorrectly handled certain files.
An attacker could possibly use these issues to cause a denial of
service, or possibly execute arbitrary code. These issues were only
addressed in Ubuntu 16.04 ESM. (CVE-2012-1148, CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2018-20843, CVE-2019-15903,
CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824,
CVE-2022-22825, CVE-2022-22826, CVE-2022-22827)
It was discovered that Expat, that is integrated in xmltok library,
incorrectly handled encoding validation of certain files. An attacker
could possibly use this issue to cause a denial of service, or
possibly execute arbitrary code. (CVE-2022-25235)
It was discovered
GHSA
GHSA-6rvw-hw83-3745: addBinding in xmlparse
ghsa_unreviewed·2022-02-10
CVE-2022-22822 [CRITICAL] CWE-190 GHSA-6rvw-hw83-3745: addBinding in xmlparse
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
OSV
CVE-2022-22822: addBinding in xmlparse
osv·2022-01-10·CVSS 9.8
CVE-2022-22822 [CRITICAL] CVE-2022-22822: addBinding in xmlparse
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Ubuntu
xmltok library vulnerabilities
vendor_ubuntu·2025-01-13·CVSS 6.8
CVE-2019-15903 [MEDIUM] xmltok library vulnerabilities
Title: xmltok library vulnerabilities
Summary: Several security issues were fixed in libxmltok.
It was discovered that Expat, contained within the xmltok library,
incorrectly handled malformed XML data. If a user or application were
tricked into opening a crafted XML file, an attacker could cause a denial
of service, or possibly execute arbitrary code. (CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2019-15903)
It was discovered that Expat, contained within the xmltok library,
incorrectly handled XML data containing a large number of colons, which
could lead to excessive resource consumption. If a user or application
were tricked into opening a crafted XML file, an attacker could possibly
use this issue to cause a denial of service. (CVE-2018-20843)
It was discovered that Expat, cont
Palo Alto
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-10-29·CVSS 9.8
CVE-2019-17006 [CRITICAL] PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2019-17006 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-3518 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-25219 This CVE is fixed in PAN-OS 10.2.3, and all later versions of PAN-OS. CVE-2021-27645 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions of PAN-OS. CVE-2021-34798 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions o
CISA ICS
Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
cisa_ics·2023-10-05·CVSS 8.8
[HIGH] Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
ICS Advisory
##
Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
Release DateOctober 05, 2023
Alert CodeICSA-23-278-01
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: AFS65x, AFF66x, AFS67x, AFR67x Series
- Vulnerabilities: Incorrect Calculation, Integer Overflow or Wraparound, Improper Encoding or Escaping of Output, Exposure of Resource to Wrong Sphere
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities by an attacker could have a high impact on availability, integrity, and confidentiality of the targeted devices.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Hitachi Energy products and versions are affecte
Android
CVE-2022-22822: Android Security Bulletin 2022-09-01
CVE: CVE-2022-22822
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L
References: A-219942275
vendor_android·2022-09-01·CVSS 9.8
CVE-2022-22822 [CRITICAL] CVE-2022-22822: Android Security Bulletin 2022-09-01
CVE: CVE-2022-22822
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L
References: A-219942275
Android Security Bulletin 2022-09-01
CVE: CVE-2022-22822
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L
References: A-219942275
Ubuntu
xmltok library vulnerabilities
vendor_ubuntu·2022-07-19·CVSS 5.0
CVE-2021-46143 [MEDIUM] xmltok library vulnerabilities
Title: xmltok library vulnerabilities
Summary: Several security issues were fixed in libxmltok.
Tim Boddy, Gustavo Grieco and others discovered that Expat, that is
integrated in xmltok library, incorrectly handled certain files.
An attacker could possibly use these issues to cause a denial of
service, or possibly execute arbitrary code. These issues were only
addressed in Ubuntu 16.04 ESM. (CVE-2012-1148, CVE-2015-1283,
CVE-2016-0718, CVE-2016-4472, CVE-2018-20843, CVE-2019-15903,
CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824,
CVE-2022-22825, CVE-2022-22826, CVE-2022-22827)
It was discovered that Expat, that is integrated in xmltok library,
incorrectly handled encoding validation of certain files. An attacker
could possibly use this issue to cause a denial of service, o
CISA ICS
Siemens SINEMA Remote Connect Server
cisa_ics·2022-06-16·CVSS 3.7
[LOW] Siemens SINEMA Remote Connect Server
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEMA Remote Connect Server
Last RevisedJune 16, 2022
Alert CodeICSA-22-167-17
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEMA Remote Connect Server
- Vulnerabilities: Multiple
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges, disclose information, or allow code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Siemens products are affected:
- Siemens SINEMA Remote Connect Server: All v
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2022-02-21
CVE-2022-22823 Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Several security issues were fixed in Expat.
It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
expat: Integer overflow in addBinding in xmlparse.c
vendor_redhat·2022-01-15·CVSS 9.8
CVE-2022-22822 [CRITICAL] CWE-190 expat: Integer overflow in addBinding in xmlparse.c
expat: Integer overflow in addBinding in xmlparse.c
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
expat (libexpat) is susceptible to a software flaw that causes process interruption. When processing a large number of prefixed XML attributes on a single tag libexpat can terminate unexpectedly due to integer overflow. The highest threat from this vulnerability is to availability confidentiality and integrity.
Statement: This is an important rather than a critical vulnerability due to its practical limitations. The flaw arises from unsafe left-shift operations in storeAtts() within libexpat, which, under extreme conditions (e.g., over 229 prefixed attributes), can lead to undefined behavior, memory mismanagement, and denial-of-service (DoS). However
Microsoft
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
vendor_msrc·2022-01-11·CVSS 9.8
CVE-2022-22822 [CRITICAL] CWE-190 addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Remediation: CBL-Mariner Rel
Debian
CVE-2022-22822: expat - addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer ove...
vendor_debian·2022·CVSS 9.8
CVE-2022-22822 [CRITICAL] CVE-2022-22822: expat - addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer ove...
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Scope: local
bookworm: resolved (fixed in 2.4.3-1)
bullseye: resolved (fixed in 2.2.10-2+deb11u1)
forky: resolved (fixed in 2.4.3-1)
sid: resolved (fixed in 2.4.3-1)
trixie: resolved (fixed in 2.4.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
Recent expat CVEs
bugzilla·2022-02-10·CVSS 8.8
[HIGH] Recent expat CVEs
Recent expat CVEs
Lately some expat CVEs popped up [1], the expat is sandboxed in the version 96+
but the ESR seems not to be covered. Could you please investigate if the vulnerabilities has any relevancy for the Firefox?
[1] https://nvd.nist.gov/vuln/search/results?form_type=Basic&results_type=overview&query=expat&search_type=all&isCpeNameSearch=false
Discussion:
[Tracking Requested - why for this release]: possible sec issues
---
Bobby, do you think RLBoxing expat on ESR was feasible?
(as a possible alternative to updating expat)
---
* CVE-2021-45960, CVE-2021-46143, CVE-2022-22822 to CVE-2022-22827: needs to be verified, but on first glance I don't think we allow enough data into the parser to hit these.
* CVE-2022-23852: doesn't affect us, only affects "configurations with a n
Bugzilla
CVE-2022-22822 expat: Integer overflow in addBinding in xmlparse.c
bugzilla·2022-01-24·CVSS 9.8
CVE-2022-22822 [CRITICAL] CVE-2022-22822 expat: Integer overflow in addBinding in xmlparse.c
CVE-2022-22822 expat: Integer overflow in addBinding in xmlparse.c
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
References:
https://github.com/libexpat/libexpat/pull/539
http://www.openwall.com/lists/oss-security/2022/01/17/3
Discussion:
Created expat tracking bugs for this issue:
Affects: fedora-all [bug 2044458]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2022:0951 https://access.redhat.com/errata/RHSA-2022:0951
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2022:1069 https://access.redhat.com/errata/RHSA-2022:1069
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://a
http://www.openwall.com/lists/oss-security/2022/01/17/3https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdfhttps://github.com/libexpat/libexpat/pull/539https://security.gentoo.org/glsa/202209-24https://www.debian.org/security/2022/dsa-5073https://www.tenable.com/security/tns-2022-05http://www.openwall.com/lists/oss-security/2022/01/17/3https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdfhttps://github.com/libexpat/libexpat/pull/539https://security.gentoo.org/glsa/202209-24https://www.debian.org/security/2022/dsa-5073https://www.tenable.com/security/tns-2022-05
2022-01-10
Published