CVE-2022-25313
published 2022-02-18CVE-2022-25313: In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
PriorityP434medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
3.29%
87.5th percentile
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | expat | < expat 2.4.5-1 (bookworm) | expat 2.4.5-1 (bookworm) |
| debian | libxmltok | < expat 2.4.5-1 (bookworm) | expat 2.4.5-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libexpat_project | libexpat | < 2.4.5 | 2.4.5 |
| msrc | cbl2_expat_2.4.8-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_expat_2.4.6-1_on_cbl_mariner_1.0 | — | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| paloalto | pan-os | — | — |
| siemens | sinema_remote_connect_server | < 3.1 | 3.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
vendor_paloalto·2025-07-09·CVSS 7.5
CVE-2018-6594 [HIGH] PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2018-6594 This CVE is fixed in PAN-OS 10.2.17, 11.1.11, 11.2.8, 12.1.2, and all later versions of PAN-OS CVE-2018-25032 This CVE is fixed in PAN-OS 10.1.7, 10.2.2, and all later versions of PAN-OS CVE-2019-5827 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13750 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13751 This CVE is fixed in PAN-OS 11.1.4, and all later versions
Palo Alto
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
vendor_paloalto·2025-07-09·CVSS 7.5
CVE-2023-38546 [HIGH] PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2018-6594 This CVE is fixed in PAN-OS 10.2.17, 11.1.11, 11.2.8, 12.1.2, and all later versions of PAN-OS CVE-2018-25032 This CVE is fixed in PAN-OS 10.1.7, 10.2.2, and all later versions of PAN-OS CVE-2019-5827 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13750 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13751 This CVE is fixed in PAN-OS 11.1.4, and all later versions
CISA ICS
Siemens SINEMA Remote Connect Server
cisa_ics·2022-06-16·CVSS 3.7
[LOW] Siemens SINEMA Remote Connect Server
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEMA Remote Connect Server
Last RevisedJune 16, 2022
Alert CodeICSA-22-167-17
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEMA Remote Connect Server
- Vulnerabilities: Multiple
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges, disclose information, or allow code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Siemens products are affected:
- Siemens SINEMA Remote Connect Server: All v
Ubuntu
Expat vulnerabilities and regression
vendor_ubuntu·2022-03-10·CVSS 9.8
CVE-2022-25314 [CRITICAL] Expat vulnerabilities and regression
Title: Expat vulnerabilities and regression
Summary: Several security issues and a regression were fixed in Expat.
USN-5288-1 fixed several vulnerabilities in Expat. For CVE-2022-25236 it
caused a regression and an additional patch was required. This update address
this regression and several other vulnerabilities.
It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2022-25313)
It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash
or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, and Ubuntu 21.10. (CVE-2022-25314)
It was discovered that Expat incorrectly handled certain files.
An attacker cou
Red Hat
expat: Stack exhaustion in doctype parsing
vendor_redhat·2022-02-19·CVSS 6.5
CVE-2022-25313 [MEDIUM] CWE-776 expat: Stack exhaustion in doctype parsing
expat: Stack exhaustion in doctype parsing
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
A flaw was found in expat. A stack exhaustion in doctype parsing could be triggered by a file with a large number of opening braces, resulting in a denial of service.
Statement: This flaw affects applications that leverage expat to parse untrusted XML files. Applications which only parse trusted XML files or do not process XML files at all are not affected by this flaw.
Mitigation: There is no known mitigation other than restricting applications using the expat library from processing untrusted XML content.
Package: expat (Red Hat Enterprise Linux 6) - Out of support scope
Package: expat (Red Hat Enterpr
Microsoft
In Expat (aka libexpat) before 2.4.5 an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
vendor_msrc·2022-02-08·CVSS 6.5
CVE-2022-25313 [MEDIUM] CWE-674 In Expat (aka libexpat) before 2.4.5 an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
In Expat (aka libexpat) before 2.4.5 an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Custome
Debian
CVE-2022-25313: expat - In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion i...
vendor_debian·2022·CVSS 6.5
CVE-2022-25313 [MEDIUM] CVE-2022-25313: expat - In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion i...
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
Scope: local
bookworm: resolved (fixed in 2.4.5-1)
bullseye: resolved (fixed in 2.2.10-2+deb11u2)
forky: resolved (fixed in 2.4.5-1)
sid: resolved (fixed in 2.4.5-1)
trixie: resolved (fixed in 2.4.5-1)
OSV
expat vulnerabilities and regression
osv·2022-03-10·CVSS 9.8
CVE-2022-25236 [CRITICAL] expat vulnerabilities and regression
expat vulnerabilities and regression
USN-5288-1 fixed several vulnerabilities in Expat. For CVE-2022-25236 it
caused a regression and an additional patch was required. This update address
this regression and several other vulnerabilities.
It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2022-25313)
It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash
or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, and Ubuntu 21.10. (CVE-2022-25314)
It was discovered that Expat incorrectly handled certain files.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. (CVE-202
GHSA
GHSA-3gf2-723m-w3fv: In Expat (aka libexpat) before 2
ghsa_unreviewed·2022-02-19
CVE-2022-25313 [MEDIUM] CWE-400 GHSA-3gf2-723m-w3fv: In Expat (aka libexpat) before 2
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
OSV
CVE-2022-25313: In Expat (aka libexpat) before 2
osv·2022-02-18·CVSS 6.5
CVE-2022-25313 [MEDIUM] CVE-2022-25313: In Expat (aka libexpat) before 2
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-25313 expat: Stack exhaustion in doctype parsing
bugzilla·2022-02-21·CVSS 6.5
CVE-2022-25313 [MEDIUM] CVE-2022-25313 expat: Stack exhaustion in doctype parsing
CVE-2022-25313 expat: Stack exhaustion in doctype parsing
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
https://github.com/libexpat/libexpat/pull/558
http://www.openwall.com/lists/oss-security/2022/02/19/1
Discussion:
Created expat tracking bugs for this issue:
Affects: fedora-all [bug 2056351]
Created mingw-expat tracking bugs for this issue:
Affects: fedora-all [bug 2056352]
---
Upstream commit:
https://github.com/libexpat/libexpat/commit/9b4ce651b26557f16103c3a366c91934ecd439ab
---
Created xmlrpc-c tracking bugs for this issue:
Affects: fedora-all [bug 2057433]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2022:5244 https://acc
Bugzilla
Recent expat CVEs
bugzilla·2022-02-10·CVSS 8.8
[HIGH] Recent expat CVEs
Recent expat CVEs
Lately some expat CVEs popped up [1], the expat is sandboxed in the version 96+
but the ESR seems not to be covered. Could you please investigate if the vulnerabilities has any relevancy for the Firefox?
[1] https://nvd.nist.gov/vuln/search/results?form_type=Basic&results_type=overview&query=expat&search_type=all&isCpeNameSearch=false
Discussion:
[Tracking Requested - why for this release]: possible sec issues
---
Bobby, do you think RLBoxing expat on ESR was feasible?
(as a possible alternative to updating expat)
---
* CVE-2021-45960, CVE-2021-46143, CVE-2022-22822 to CVE-2022-22827: needs to be verified, but on first glance I don't think we allow enough data into the parser to hit these.
* CVE-2022-23852: doesn't affect us, only affects "configurations with a n
http://www.openwall.com/lists/oss-security/2022/02/19/1https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdfhttps://github.com/libexpat/libexpat/pull/558https://lists.debian.org/debian-lts-announce/2022/03/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/https://security.gentoo.org/glsa/202209-24https://security.netapp.com/advisory/ntap-20220303-0008/https://www.debian.org/security/2022/dsa-5085https://www.oracle.com/security-alerts/cpuapr2022.htmlhttp://www.openwall.com/lists/oss-security/2022/02/19/1https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdfhttps://github.com/libexpat/libexpat/pull/558https://lists.debian.org/debian-lts-announce/2022/03/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM/https://security.gentoo.org/glsa/202209-24https://security.netapp.com/advisory/ntap-20220303-0008/https://www.debian.org/security/2022/dsa-5085https://www.oracle.com/security-alerts/cpuapr2022.html
2022-02-18
Published