CVE-2022-23990
published 2022-01-26CVE-2022-23990: Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.99%
89.4th percentile
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | expat | < expat 2.4.3-3 (bookworm) | expat 2.4.3-3 (bookworm) |
| debian | libxmltok | < expat 2.4.3-3 (bookworm) | expat 2.4.3-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| android | — | — | |
| libexpat_project | libexpat | < 2.4.4 | 2.4.4 |
| msrc | cbl2_expat_2.4.8-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_expat_2.4.4-1_on_cbl_mariner_1.0 | — | — |
| oracle | communications_metasolv_solution | — | — |
| platform | external_expat | >= 10:0 < 10:2022-09-01 | 10:2022-09-01 |
| platform | external_expat | >= 11:0 < 11:2022-09-01 | 11:2022-09-01 |
| platform | external_expat | >= 12:0 < 12:2022-09-01 | 12:2022-09-01 |
| platform | external_expat | >= 12L:0 < 12L:2022-09-01 | 12L:2022-09-01 |
| siemens | sinema_remote_connect_server | < 3.1 | 3.1 |
| tenable | nessus | < 8.15.3 | 8.15.3 |
| tenable | nessus | >= 10.0.0 < 10.1.1 | 10.1.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_oracle9.8HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-23990: In closeString of xmlparse
osv·2022-09-01
CVE-2022-23990 CVE-2022-23990: In closeString of xmlparse
In closeString of xmlparse.c, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA
GHSA-r3g2-gw56-v728: Expat (aka libexpat) before 2
ghsa_unreviewed·2022-02-10
CVE-2022-23990 [CRITICAL] CWE-190 GHSA-r3g2-gw56-v728: Expat (aka libexpat) before 2
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
OSV
CVE-2022-23990: Expat (aka libexpat) before 2
osv·2022-01-26·CVSS 7.5
CVE-2022-23990 [HIGH] CVE-2022-23990: Expat (aka libexpat) before 2
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
CISA ICS
Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
cisa_ics·2023-10-05·CVSS 8.8
[HIGH] Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
ICS Advisory
##
Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
Release DateOctober 05, 2023
Alert CodeICSA-23-278-01
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: AFS65x, AFF66x, AFS67x, AFR67x Series
- Vulnerabilities: Incorrect Calculation, Integer Overflow or Wraparound, Improper Encoding or Escaping of Output, Exposure of Resource to Wrong Sphere
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities by an attacker could have a high impact on availability, integrity, and confidentiality of the targeted devices.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Hitachi Energy products and versions are affecte
Android
CVE-2022-23990: Android Security Bulletin 2022-09-01
CVE: CVE-2022-23990
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L
References: A-221256678
vendor_android·2022-09-01·CVSS 7.5
CVE-2022-23990 [HIGH] CVE-2022-23990: Android Security Bulletin 2022-09-01
CVE: CVE-2022-23990
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L
References: A-221256678
Android Security Bulletin 2022-09-01
CVE: CVE-2022-23990
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L
References: A-221256678
CISA ICS
Siemens SINEMA Remote Connect Server
cisa_ics·2022-06-16·CVSS 3.7
[LOW] Siemens SINEMA Remote Connect Server
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEMA Remote Connect Server
Last RevisedJune 16, 2022
Alert CodeICSA-22-167-17
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEMA Remote Connect Server
- Vulnerabilities: Multiple
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges, disclose information, or allow code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Siemens products are affected:
- Siemens SINEMA Remote Connect Server: All v
Oracle
Oracle Oracle Communications Applications Risk Matrix: User Interface (LibExpat) — CVE-2022-23990
vendor_oracle·2022-04-15·CVSS 9.8
CVE-2022-23990 [HIGH] Oracle Oracle Communications Applications Risk Matrix: User Interface (LibExpat) — CVE-2022-23990
Oracle Oracle Communications Applications Risk Matrix: User Interface (LibExpat) vulnerability
CVE: CVE-2022-23990
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2022-02-21
CVE-2022-22823 Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Several security issues were fixed in Expat.
It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
expat: integer overflow in the doProlog function
vendor_redhat·2022-01-26·CVSS 7.5
CVE-2022-23990 [HIGH] CWE-190 expat: integer overflow in the doProlog function
expat: integer overflow in the doProlog function
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
A flaw was found in expat. The vulnerability occurs due to large content in element type declarations when there is an element declaration handler present which leads to an integer overflow. This flaw allows an attacker to inject an unsigned integer, leading to a crash or a denial of service.
Statement: Red Hat Product Security marked this flaw as Moderate Impact because the vulnerability includes a flaw that is present in a program’s source code but to which no current or theoretically possible, but unproven, exploitation vectors exist or were found during the technical analysis of the flaw.
Package: compat-expat1 (Red Hat Enterprise Linux 6) - Out of su
Microsoft
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
vendor_msrc·2022-01-11·CVSS 7.5
CVE-2022-23990 [HIGH] CWE-190 Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Remediation: CBL-Mariner Releas
Debian
CVE-2022-23990: expat - Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog functi...
vendor_debian·2022·CVSS 7.5
CVE-2022-23990 [HIGH] CVE-2022-23990: expat - Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog functi...
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
Scope: local
bookworm: resolved (fixed in 2.4.3-3)
bullseye: resolved (fixed in 2.2.10-2+deb11u1)
forky: resolved (fixed in 2.4.3-3)
sid: resolved (fixed in 2.4.3-3)
trixie: resolved (fixed in 2.4.3-3)
No detection rules found.
No public exploits indexed.
Bugzilla
Recent expat CVEs
bugzilla·2022-02-10·CVSS 8.8
[HIGH] Recent expat CVEs
Recent expat CVEs
Lately some expat CVEs popped up [1], the expat is sandboxed in the version 96+
but the ESR seems not to be covered. Could you please investigate if the vulnerabilities has any relevancy for the Firefox?
[1] https://nvd.nist.gov/vuln/search/results?form_type=Basic&results_type=overview&query=expat&search_type=all&isCpeNameSearch=false
Discussion:
[Tracking Requested - why for this release]: possible sec issues
---
Bobby, do you think RLBoxing expat on ESR was feasible?
(as a possible alternative to updating expat)
---
* CVE-2021-45960, CVE-2021-46143, CVE-2022-22822 to CVE-2022-22827: needs to be verified, but on first glance I don't think we allow enough data into the parser to hit these.
* CVE-2022-23852: doesn't affect us, only affects "configurations with a n
Bugzilla
CVE-2022-23990 expat: integer overflow in the doProlog function
bugzilla·2022-01-31·CVSS 7.5
CVE-2022-23990 [HIGH] CVE-2022-23990 expat: integer overflow in the doProlog function
CVE-2022-23990 expat: integer overflow in the doProlog function
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
https://github.com/libexpat/libexpat/pull/551
Discussion:
Created expat tracking bugs for this issue:
Affects: fedora-all [bug 2050215]
Created mingw-expat tracking bugs for this issue:
Affects: fedora-all [bug 2050214]
---
I have this vulnerability shown by Twistlock scans - but its on ubi-minimal 8.6.x. When I check on the Red Hat Advisory here- https://access.redhat.com/security/cve/CVE-2022-23990, it doesn't mention about RHEL v8.x; does that mean, this RHEL v8.x is NOT AFFECTED
by this vulnerability(CVE-2022-23990) ??
---
This issue has been addressed in the following products:
Red Hat JBoss Core Services
Via RHSA-2022:7144 h
https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdfhttps://github.com/libexpat/libexpat/pull/551https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/34NXVL2RZC2YZRV74ZQ3RNFB7WCEUP7D/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7FF2UH7MPXKTADYSJUAHI2Y5UHBSHUH/https://security.gentoo.org/glsa/202209-24https://www.debian.org/security/2022/dsa-5073https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.tenable.com/security/tns-2022-05https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdfhttps://github.com/libexpat/libexpat/pull/551https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/34NXVL2RZC2YZRV74ZQ3RNFB7WCEUP7D/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7FF2UH7MPXKTADYSJUAHI2Y5UHBSHUH/https://security.gentoo.org/glsa/202209-24https://www.debian.org/security/2022/dsa-5073https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.tenable.com/security/tns-2022-05
2022-01-26
Published