CVE-2022-22822Integer Overflow or Wraparound in External Expat

Severity
9.8CRITICALNVD
OSV5.0
EPSS
1.3%
top 20.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateJan 13

Description

addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

Androidplatform/external_expat10:010:2022-09-01+3
NVDtenable/nessus10.0.010.1.1+1

Also affects: Debian Linux 10.0, 11.0

Patches

🔴Vulnerability Details

5
OSV
CVE-2022-22822: In storeAtts of xmlparse2022-09-01
OSV
libxmltok vulnerabilities2022-07-19
GHSA
GHSA-6rvw-hw83-3745: addBinding in xmlparse2022-02-10
OSV
CVE-2022-22822: addBinding in xmlparse2022-01-10
CVEList
CVE-2022-22822: addBinding in xmlparse2022-01-08

📋Vendor Advisories

7
Ubuntu
xmltok library vulnerabilities2025-01-13
Android
CVE-2022-22822: Android Security Bulletin 2022-09-01 CVE: CVE-2022-22822 Severity: HIGH Type: EoP Affected AOSP versions: 10, 11, 12, 12L References: A-2199422752022-09-01
Ubuntu
xmltok library vulnerabilities2022-07-19
Ubuntu
Expat vulnerabilities2022-02-21
Red Hat
expat: Integer overflow in addBinding in xmlparse.c2022-01-15
CVE-2022-22822 — Integer Overflow or Wraparound | cvebase