vulnerability

Amazon Linux 2023: CVE-2022-22826: Critical priority package update for expat

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Jan 15, 2022
Added
Feb 17, 2025
Modified
Feb 17, 2025

Description

nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
expat (libexpat) is susceptible to a software flaw that causes process interruption. When processing a large number of prefixed XML attributes on a single tag can libexpat can terminate unexpectedly due to integer overflow. The highest threat from this vulnerability is to availability, confidentiality and integrity.

Solution(s)

amazon-linux-2023-upgrade-expatamazon-linux-2023-upgrade-expat-debuginfoamazon-linux-2023-upgrade-expat-debugsourceamazon-linux-2023-upgrade-expat-develamazon-linux-2023-upgrade-expat-static
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.