CVE-2022-43680
published 2022-10-24CVE-2022-43680: In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.26%
81.0th percentile
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | expat | < expat 2.5.0-1 (bookworm) | expat 2.5.0-1 (bookworm) |
| debian | libxmltok | < expat 2.5.0-1 (bookworm) | expat 2.5.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| android | — | — | |
| libexpat_project | libexpat | <= 2.4.9 | — |
| msrc | azl3_cmake_3.30.3-6_on_azure_linux_3.0 | — | — |
| msrc | cbl2_expat_2.5.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_expat_2.5.0-1_on_cbl_mariner_1.0 | — | — |
| platform | external_expat | >= 10:0 < 10:2023-02-01 | 10:2023-02-01 |
| platform | external_expat | >= 11:0 < 11:2023-02-01 | 11:2023-02-01 |
| platform | external_expat | >= 12:0 < 12:2023-02-01 | 12:2023-02-01 |
| platform | external_expat | >= 12L:0 < 12L:2023-02-01 | 12L:2023-02-01 |
| platform | external_expat | >= 13:0 < 13:2023-02-01 | 13:2023-02-01 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Enterprise Manager Install (LibExpat) — CVE-2022-43680
vendor_oracle·2023-10-15·CVSS 7.5
CVE-2022-43680 [HIGH] Oracle Oracle Enterprise Manager Risk Matrix: Enterprise Manager Install (LibExpat) — CVE-2022-43680
Oracle Oracle Enterprise Manager Risk Matrix: Enterprise Manager Install (LibExpat) vulnerability
CVE: CVE-2022-43680
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Text (LibExpat) — CVE-2022-43680
vendor_oracle·2023-07-15·CVSS 6.5
CVE-2022-43680 [HIGH] Oracle Oracle Database Server Risk Matrix: Oracle Text (LibExpat) — CVE-2022-43680
Oracle Oracle Database Server Risk Matrix: Oracle Text (LibExpat) vulnerability
CVE: CVE-2022-43680
CVSS: 6.5
Protocol: Oracle Net
Remote exploit: No
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
CISA ICS
Hitachi Energy’s AFS65x, AFS67x, AFR67x and AFF66x Products
cisa_ics·2023-05-23·CVSS 8.1
[HIGH] Hitachi Energy’s AFS65x, AFS67x, AFR67x and AFF66x Products
ICS Advisory
##
Hitachi Energy’s AFS65x, AFS67x, AFR67x and AFF66x Products
Release DateMay 23, 2023
Alert CodeICSA-23-143-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: AFS65x, AFS67x, AFR67x and AFF66x series products
- Vulnerabilities: Use After Free
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information or lead to a Denial-of-Service (DoS).
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Hitachi Energy’s AFS65x, AFS67x, AFR67x and AFF66x series products, are affected:
- AFS660/665S, AFS660/665C, AFS670v2: Firmware 7.1.05 and earlier
- AFS670/675, AFR67x: Firmware
CISA ICS
Siemens SINEC NMS Third-Party
cisa_ics·2023-05-11·CVSS 9.8
[CRITICAL] Siemens SINEC NMS Third-Party
ICS Advisory
##
Siemens SINEC NMS Third-Party
Release DateMay 11, 2023
Alert CodeICSA-23-131-05
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Third-party components libexpat and libcurl in SINEC NMS
- Vulnerabilities: Expected Behavior Violation, Improper Validation of Syntactic Correctness of Input, Stack-based Buffer Overflow, Use After Free, Double Free, Cleartext Tran
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Third Party (LibExpat) — CVE-2022-43680
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2022-43680 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Third Party (LibExpat) — CVE-2022-43680
Oracle Oracle Financial Services Applications Risk Matrix: Third Party (LibExpat) vulnerability
CVE: CVE-2022-43680
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2023-02-28
CVE-2022-40674 Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Expat could be made to crash or execute arbitrary code.
USN-5638-1 fixed several vulnerabilities in Expat. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Rhodri James discovered that Expat incorrectly handled memory when
processing certain malformed XML files. An attacker could possibly
use this issue to cause a crash or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Android
CVE-2022-43680: Android Security Bulletin 2023-02-01
CVE: CVE-2022-43680
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-255449293
vendor_android·2023-02-01·CVSS 7.5
CVE-2022-43680 [HIGH] CVE-2022-43680: Android Security Bulletin 2023-02-01
CVE: CVE-2022-43680
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-255449293
Android Security Bulletin 2023-02-01
CVE: CVE-2022-43680
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-255449293
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Third-party Jars (Libexpat) — CVE-2022-43680
vendor_oracle·2023-01-15·CVSS 7.5
CVE-2022-43680 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Centralized Third-party Jars (Libexpat) — CVE-2022-43680
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Third-party Jars (Libexpat) vulnerability
CVE: CVE-2022-43680
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Ubuntu
Expat vulnerability
vendor_ubuntu·2022-11-23·CVSS 7.5
CVE-2022-43680 [HIGH] Expat vulnerability
Title: Expat vulnerability
Summary: Expat could be made to crash or execute arbitrary code.
USN-5638-1 fixed a vulnerability in Expat. This update provides
the corresponding updates for Ubuntu 16.04 ESM, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-43680)
This update also fixes a minor regression introduced in
Ubuntu 18.04 LTS.
We apologize for the inconvenience.
Original advisory details:
Rhodri James discovered that Expat incorrectly handled memory when
processing certain malformed XML files. An attacker could possibly
use this issue to cause a crash or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2022-11-17·CVSS 7.5
CVE-2022-43680 [HIGH] Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Expat could be made to crash or execute arbitrary code.
USN-5638-1 fixed a vulnerability in Expat. This update provides
the corresponding updates for Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS.
It was discovered that Expat incorrectly handled memory in out-of-memory
situations. An attacker could possibly use this issue to cause a crash,
resulting in a denial of service, or possibly execute arbitrary code.
This issue only affected Ubuntu 18.04 LTS. (CVE-2022-43680)
Original advisory details:
Rhodri James discovered that Expat incorrectly handled memory when
processing certain malformed XML files. An attacker could possibly
use this issue to cause a crash or execute arbitrary code.
Instructions: In general, a standard system update wil
BSD
OpenBSD 7.1 Errata 012: SECURITY FIX
bsd_advisories·2022-11-01·CVSS 7.5
CVE-2022-43680 [HIGH] OpenBSD 7.1 Errata 012: SECURITY FIX
OpenBSD 7.1 Errata 012: SECURITY FIX
012: SECURITY FIX: November 1, 2022
All architectures In libexpat fix heap use-after-free vulnerability CVE-2022-43680.
BSD
OpenBSD 7.2 Errata 004: SECURITY FIX
bsd_advisories·2022-11-01·CVSS 7.5
CVE-2022-43680 [HIGH] OpenBSD 7.2 Errata 004: SECURITY FIX
OpenBSD 7.2 Errata 004: SECURITY FIX
004: SECURITY FIX: November 1, 2022
All architectures In libexpat fix heap use-after-free vulnerability CVE-2022-43680.
Red Hat
expat: use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate
vendor_redhat·2022-10-24·CVSS 7.5
CVE-2022-43680 [HIGH] CWE-416 expat: use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate
expat: use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
A use-after-free flaw was found in the Expat package, caused by destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations. This may lead to availability disruptions.
Statement: This vulnerability can only happen under special (out-of-memory) conditions, thus it is not possible to exploit on every possible system that has expat installed. Additionally as the flaw is only capable of causing a Denial of Service, Red Hat rates the impact as Moderate.
Package: compat-expat1 (Red Hat Enterprise Li
Microsoft
In libexpat through 2.4.9 there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
vendor_msrc·2022-10-11·CVSS 7.5
CVE-2022-43680 [HIGH] CWE-416 In libexpat through 2.4.9 there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
In libexpat through 2.4.9 there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Marine
Debian
CVE-2022-43680: expat - In libexpat through 2.4.9, there is a use-after free caused by overeager destruc...
vendor_debian·2022·CVSS 7.5
CVE-2022-43680 [HIGH] CVE-2022-43680: expat - In libexpat through 2.4.9, there is a use-after free caused by overeager destruc...
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
Scope: local
bookworm: resolved (fixed in 2.5.0-1)
bullseye: resolved (fixed in 2.2.10-2+deb11u5)
forky: resolved (fixed in 2.5.0-1)
sid: resolved (fixed in 2.5.0-1)
trixie: resolved (fixed in 2.5.0-1)
OSV
CVE-2022-43680: In parserCreate of xmlparse
osv·2023-02-01
CVE-2022-43680 CVE-2022-43680: In parserCreate of xmlparse
In parserCreate of xmlparse.c, there is a possible use after free that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
expat vulnerability
osv·2022-11-23·CVSS 7.5
CVE-2022-43680 [HIGH] expat vulnerability
expat vulnerability
USN-5638-1 fixed a vulnerability in Expat. This update provides
the corresponding updates for Ubuntu 16.04 ESM, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-43680)
This update also fixes a minor regression introduced in
Ubuntu 18.04 LTS.
We apologize for the inconvenience.
Original advisory details:
Rhodri James discovered that Expat incorrectly handled memory when
processing certain malformed XML files. An attacker could possibly
use this issue to cause a crash or execute arbitrary code.
OSV
expat vulnerabilities
osv·2022-11-17·CVSS 7.5
CVE-2022-43680 [HIGH] expat vulnerabilities
expat vulnerabilities
USN-5638-1 fixed a vulnerability in Expat. This update provides
the corresponding updates for Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS.
It was discovered that Expat incorrectly handled memory in out-of-memory
situations. An attacker could possibly use this issue to cause a crash,
resulting in a denial of service, or possibly execute arbitrary code.
This issue only affected Ubuntu 18.04 LTS. (CVE-2022-43680)
Original advisory details:
Rhodri James discovered that Expat incorrectly handled memory when
processing certain malformed XML files. An attacker could possibly
use this issue to cause a crash or execute arbitrary code.
OSV
CVE-2022-43680: In libexpat through 2
osv·2022-10-24·CVSS 7.5
CVE-2022-43680 [HIGH] CVE-2022-43680: In libexpat through 2
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
GHSA
GHSA-4hjv-8mmr-jxwv: In libexpat through 2
ghsa_unreviewed·2022-10-24
CVE-2022-43680 [HIGH] CWE-416 GHSA-4hjv-8mmr-jxwv: In libexpat through 2
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2023/12/28/5http://www.openwall.com/lists/oss-security/2024/01/03/5https://github.com/libexpat/libexpat/issues/649https://github.com/libexpat/libexpat/pull/616https://github.com/libexpat/libexpat/pull/650https://lists.debian.org/debian-lts-announce/2022/10/msg00033.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJ5VY2VYXE4WTRGQ6LMGLF6FV3SY37YE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BY4OPSIB33ETNUXZY2UPZ4NGQ3OKDY4D/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPQVIF6TOJNY2T3ZZETFKR4G34FFREBQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFCOMBSOJKLIKCGCJWHLJXO4EVYBG7AR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IUJ2BULJTZ2BMSKQHB6US674P55UCWWS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XG5XOOB7CD55CEE6OJYKSACSIMQ4RWQ6/https://security.gentoo.org/glsa/202210-38https://security.netapp.com/advisory/ntap-20221118-0007/https://www.debian.org/security/2022/dsa-5266http://www.openwall.com/lists/oss-security/2023/12/28/5http://www.openwall.com/lists/oss-security/2024/01/03/5https://github.com/libexpat/libexpat/issues/649https://github.com/libexpat/libexpat/pull/616https://github.com/libexpat/libexpat/pull/650https://lists.debian.org/debian-lts-announce/2022/10/msg00033.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJ5VY2VYXE4WTRGQ6LMGLF6FV3SY37YE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BY4OPSIB33ETNUXZY2UPZ4NGQ3OKDY4D/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPQVIF6TOJNY2T3ZZETFKR4G34FFREBQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFCOMBSOJKLIKCGCJWHLJXO4EVYBG7AR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IUJ2BULJTZ2BMSKQHB6US674P55UCWWS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XG5XOOB7CD55CEE6OJYKSACSIMQ4RWQ6/https://security.gentoo.org/glsa/202210-38https://security.netapp.com/advisory/ntap-20221118-0007/https://www.debian.org/security/2022/dsa-5266
2022-10-24
Published