CVE-2022-43680: Apache OpenOffice: "Use after free" fixed in libexpat
A use-after-free flaw was found in the Expat package, caused by destruction of a shared DTD in XMLExternalEntityParserCreate in out-of-memory situations. This may lead to availability disruptions.
Other sources
In libexpat through 2.4.9 there is a use-after free caused by overeager destruction of a shared DTD in XMLExternalEntityParserCreate in out-of-memory situations.
— Microsoft
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XMLExternalEntityParserCreate in out-of-memory situations.
libexpat is vulnerable to a denial of service, caused by a use-after free created by overeager destruction of a shared DTD in XMLExternalEntityParserCreate in out-of-memory situations. A remote attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/expatto a version that resolves this vulnerability.Fixed in 2.2.6-2+deb10u6Fixed in 2.2.10-2+deb11u5Fixed in 2.5.0-1Fixed in 2.5.0-2 - Upgrade
Upgrade
debian/expatto a version that resolves this vulnerability.Fixed in 2.5.0-1Fixed in 2.2.10-2+deb11u5 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 0:2.2.5-10.el8_7.1 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 0:2.4.9-1.el9_1.1 - Upgrade
Upgrade
redhat/expatto a version that resolves this vulnerability.Fixed in 2.5.0 - Upgrade
Upgrade
libexpatto a version that resolves this vulnerability.Fixed in 2.4.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2022-43680 - Compensating control
Mitigate the denial-of-service risk by restricting or rate-limiting access to any feature/service that parses untrusted XML using Expat/libexpat, until the libexpat upgrade with CVE-2022-43680 is applied.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-43680?
CVE-2022-43680 is a use-after-free vulnerability in the Expat package, specifically in the destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
What is the severity of CVE-2022-43680?
CVE-2022-43680 has a severity level of 7.5 (high).
Which software is affected by CVE-2022-43680?
CVE-2022-43680 affects the expat package in various versions on Debian, Red Hat, Google Android, and other platforms.
How can I fix CVE-2022-43680?
To fix CVE-2022-43680, update the affected expat package to the recommended versions provided by the vendor.
Where can I find more information about CVE-2022-43680?
More information about CVE-2022-43680 can be found in the references section of the vulnerability report.