CVE-2022-22826

CWE-190Integer Overflow11 documents8 sources
Severity
8.8HIGH
EPSS
0.2%
top 57.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateJan 13

Description

nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

Debianexpat< 2.2.10-2+deb11u1+3
NVDtenable/nessus10.0.010.1.1+1

Also affects: Debian Linux 10.0, 11.0

Patches

🔴Vulnerability Details

4
OSV
libxmltok vulnerabilities2022-07-19
GHSA
GHSA-q5xc-gwgw-8j5q: nextScaffoldPart in xmlparse2022-02-10
OSV
CVE-2022-22826: nextScaffoldPart in xmlparse2022-01-10
CVEList
CVE-2022-22826: nextScaffoldPart in xmlparse2022-01-08

📋Vendor Advisories

6
Ubuntu
xmltok library vulnerabilities2025-01-13
Ubuntu
xmltok library vulnerabilities2022-07-19
Ubuntu
Expat vulnerabilities2022-02-21
Red Hat
expat: Integer overflow in nextScaffoldPart in xmlparse.c2022-01-15
Microsoft
nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.2022-01-11
CVE-2022-22826 (HIGH CVSS 8.8) | nextScaffoldPart in xmlparse.c in E | cvebase.io