Use-after-free in expat - CVE-2022-40674
Published: September 21, 2022 / Updated: November 15, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in the doContent() function in xmlparse.c. A remote attacker can pass specially crafted input to the application that is using the affected library, trigger a use-after-free error and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Amazon Linux AMI
Gentoo Linux
Debian Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Red Hat Enterprise Linux Server - Extended Life Cycle Support
SUSE Enterprise Storage
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
CentOS
Red Hat Enterprise Linux for Scientific Computing
Oracle Linux
IBM AIX
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
Fedora
API Gateway
API Manager
IBM QRadar Network Packet Capture
BIG-IP
PowerScale OneFS
OpenShift sandboxed containers
OpenShift Virtualization
OpenShift API for Data Protection (OADP)
Data Lakehouse
IBM Security Verify Bridge
Service Telemetry Framework
IBM MQ Operator
Red Hat Advanced Cluster Management for Kubernetes
Ansible Automation Platform
Oracle VM Server for x86
OpenShift Logging
Tenable Nessus
Netcool Operations Insight
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Tivoli Monitoring
IBM Rational ClearCase
Telemetry Dashboard
Storage Defender – Data Protect
Liquidware
IBM supplied MQ Advanced container images
Citrix Workspace App
Webex App VDI
cflinuxfs3
PowerStore T
IBM Cloud Pak for Watson AIOps
EMC ECS
XtremIO X2
HPE OneView
Db2 Net Search Extender
Robotic Process Automation for Cloud Pak
compat-expat1 (Red Hat package)
expat (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
thunderbird (Red Hat package)
firefox (Red Hat package)
libexpat1 (Ubuntu package)
expat (Ubuntu package)
expat-static
expat-devel
expat
expat-debuginfo
expat-debuginfo-32bit
expat-debugsource
libexpat1
libexpat1-32bit
libexpat1-debuginfo
libexpat-devel
libexpat1-debuginfo-32bit
lib64expat1 (Ubuntu package)
expat-32bit-debuginfo
libexpat1-32bit-debuginfo
libexpat-devel-32bit
expat-help
expat (Debian package)
mingw32-expat
mingw64-expat
mingw-expat (Red Hat package)
dev-libs/expat
mingw-expat
python3
redhat-virtualization-host-productimg (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
firefox-debuginfo
firefox
mozilla-crashreporter-firefox-debuginfo
firefox-debugsource
thunderbird
www-client/firefox
firefox (Ubuntu package)
IBM Cloud Pak System
Red Hat OpenShift Container Platform
IBM Edge Application Manager
Nessus Network Monitor
VMware Horizon Client
HPE Moonshot 1500 Chassis Manager
IBM Tivoli Network Manager (ITNM)
SecureTransport
IBM HTTP Server
BIG-IQ Centralized Management
SINEC NMS
IBM Qradar SIEM
Cloud Pak for Security (CP4S)
NetWorker Management Console
IBM Security Guardium
BIG-IP DNS
Dell EMC VxRail Appliance
BIG-IP ASM
Cisco Jabber
Pale Moon
Mozilla Firefox
Cisco Webex Meetings
Firefox for Android
SCALANCE XCM332
RSA Authentication Manager
How to mitigate CVE-2022-40674
API Gateway - update to November 2022
API Manager - update to November 2022
OpenShift sandboxed containers - update to 1.3.1
OpenShift API for Data Protection (OADP) - addressed in versions 1.0.5, 1.1.1
Data Lakehouse - update to 1.1.0.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
IBM Security Verify Bridge - update to 1.0.13.0
Service Telemetry Framework - update to 1.5.2
compat-expat1 (Red Hat package) - update to 1.95.8-9.el6_10
Storage Defender – Data Protect - update to 2.1.4
expat (Red Hat package) - addressed in versions 2.0.1-15.el6_10, 2.1.0-15.el7_9, 2.2.5-3.el8_1.2, 2.2.5-3.el8_2.3, 2.2.5-4.el8_4.4, 2.2.5-8.el8_6.3, 2.2.10-12.el9_0.3
IBM Cloud Pak System - update to 2.3.3.6
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.4.8, 2.6.2
Red Hat OpenShift Container Platform - addressed in versions 4.9.50, 4.11.12, 4.11.45, 4.13.0
OpenShift Virtualization - addressed in versions 4.9.7, 4.11.1, 4.12.0
OpenShift Logging - addressed in versions 5.3.13, 5.4.8, 5.5.4
SecureTransport - update to 5.5-20221027
Nessus Network Monitor - update to 6.2.1
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 8, 7.5.0 Update Pack 4
Tenable Nessus - addressed in versions 8.15.7, 10.3.1
IBM supplied MQ Advanced container images - update to 9.3.0.1-r3
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Pale Moon - update to 31.3.1
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
thunderbird (Red Hat package) - addressed in versions 102.3.0-4.el7_9, 102.3.0-4.el8_1, 102.3.0-4.el8_2, 102.3.0-4.el8_4, 102.3.0-4.el8_6, 102.3.0-4.el9_0
firefox (Red Hat package) - addressed in versions 102.3.0-7.el7_9, 102.3.0-7.el8_1, 102.3.0-7.el8_2, 102.3.0-7.el8_4, 102.3.0-7.el8_6, 102.3.0-7.el9_0
Mozilla Firefox - update to 107.0
Firefox for Android - update to 107.1.0
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libexpat1 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.1.07ubuntu0.16.04.5+esm6, 2.2.5-3ubuntu0.8, 2.2.9-1ubuntu0.5, 2.4.7-1ubuntu0.1
expat (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.1.07ubuntu0.16.04.5+esm6, 2.2.5-3ubuntu0.8, 2.2.9-1ubuntu0.5, 2.4.7-1ubuntu0.1
cflinuxfs3 - update to 0.335.0
SINEC NMS - update to 1.0.3.1
Netcool Operations Insight - update to 1.6.8
Cloud Pak for Security (CP4S) - update to 1.10.12.0
expat-static - update to 2.1.0-15
expat-devel - addressed in versions 2.1.0-15, 2.2.5-8
expat - addressed in versions 2.1.0-15, 2.2.5-8
expat - addressed in versions 2.1.0-15.32, 2.5.0-1
expat - addressed in versions 2.1.0-21.25.1, 2.2.5-150000.3.22.1, 2.4.4-150400.3.9.1
expat-debuginfo - addressed in versions 2.1.0-21.25.1, 2.2.5-150000.3.22.1, 2.4.4-150400.3.9.1
expat-debuginfo-32bit - update to 2.1.0-21.25.1
expat-debugsource - addressed in versions 2.1.0-21.25.1, 2.2.5-150000.3.22.1, 2.4.4-150400.3.9.1
libexpat1 - addressed in versions 2.1.0-21.25.1, 2.2.5-150000.3.22.1, 2.4.4-150400.3.9.1
libexpat1-32bit - addressed in versions 2.1.0-21.25.1, 2.2.5-150000.3.22.1, 2.4.4-150400.3.9.1
libexpat1-debuginfo - addressed in versions 2.1.0-21.25.1, 2.2.5-150000.3.22.1, 2.4.4-150400.3.9.1
libexpat-devel - addressed in versions 2.1.0-21.25.1, 2.2.5-150000.3.22.1, 2.4.4-150400.3.9.1
libexpat1-debuginfo-32bit - update to 2.1.0-21.25.1
lib64expat1 (Ubuntu package) - update to 2.1.07ubuntu0.16.04.5+esm6
SCALANCE XCM332 - update to 2.2
expat-32bit-debuginfo - addressed in versions 2.2.5-150000.3.22.1, 2.4.4-150400.3.9.1
libexpat1-32bit-debuginfo - addressed in versions 2.2.5-150000.3.22.1, 2.4.4-150400.3.9.1
libexpat-devel-32bit - addressed in versions 2.2.5-150000.3.22.1, 2.4.4-150400.3.9.1
expat-devel - update to 2.2.9-8
expat - update to 2.2.9-8
expat-debuginfo - update to 2.2.9-8
expat-debugsource - update to 2.2.9-8
expat-help - update to 2.2.9-8
expat (Debian package) - update to 2.2.10-2+deb11u4
expat - addressed in versions 2.4.3, 2.4.9
mingw32-expat - update to 2.4.8-2
mingw64-expat - update to 2.4.8-2
mingw-expat (Red Hat package) - update to 2.4.8-2.el8
dev-libs/expat - update to 2.4.9
expat - addressed in versions 2.4.9-1.fc35, 2.4.9-1.fc36
mingw-expat - addressed in versions 2.4.9-1.fc35, 2.4.9-1.fc36, 2.4.9-1.fc37
IBM Cloud Transformation Advisor - update to 3.4.0
PowerStore T - update to 3.5.0.1-2083289
IBM Cloud Pak for Watson AIOps - update to 3.6.1
EMC ECS - update to 3.8.0.2
python3 - update to 3.9.15
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.16
redhat-virtualization-host-productimg (Red Hat package) - update to 4.5.3-1.el8
redhat-release-virtualization-host (Red Hat package) - update to 4.5.3-1.el8ev
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
IBM Tivoli Monitoring - update to 6.3.0.7 Service Pack 12
XtremIO X2 - update to 6.4.1-11
IBM QRadar Network Packet Capture - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Package 3
Dell EMC VxRail Appliance - update to 8.0.000
HPE OneView - update to 8.1
RSA Authentication Manager - update to 8.7 Patch 2
IBM Rational ClearCase - addressed in versions 9.0.2.7, 9.1.0.4, 10.0.0.1
PowerScale OneFS - addressed in versions 9.1.0.26, 9.2.1.19, 9.4.0.10, 9.5.0.6
Db2 Net Search Extender - addressed in versions 9.7.0.11, 10.1.0.6, 10.5.0.11, 11.1.4.7
NetWorker Management Console - update to 19.12.0.1
Robotic Process Automation for Cloud Pak - update to 21.0.7
firefox-debuginfo - update to 79.0-9
firefox - update to 79.0-9
mozilla-crashreporter-firefox-debuginfo - update to 79.0-9
firefox-debugsource - update to 79.0-9
thunderbird - update to 102.3.0-4.0.1
firefox - update to 102.3.0-7.0.1
www-client/firefox - update to 104
firefox (Ubuntu package) - addressed in versions 107.0+build2-0ubuntu0.18.04.1, 107.0+build2-0ubuntu0.20.04.1
External References
Related Security Bulletins
- Remote code execution in libexpat
- Slackware Linux update for expat (SSA
- Debian update for expat
- Ubuntu update for expat
- Gentoo update for Expat
- SUSE update for expat
- SUSE update for expat
- Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions update for expat
- Red Hat Enterprise Linux 8.2 Extended Update Support update for expat
- Red Hat Enterprise Linux 8.4 Extended Update Support update for expat
- Red Hat Enterprise Linux 7 update for expat
- Remote code execution in IBM HTTP Server
- Red Hat Enterprise Linux 9 update for expat
- Red Hat Enterprise Linux 8 update for expat
- Red Hat Enterprise Linux 6 Extended Lifecycle Support update for expat
- Slackware Linux update for python3
- Red Hat Enterprise Linux 6 Extended Lifecycle Support update for compat-expat1
- SUSE update for expat
- Red Hat Enterprise Linux 8.2 Extended Update Support update for thunderbird
- Red Hat Enterprise Linux 7 update for thunderbird
- Red Hat Enterprise Linux 7 update for firefox
- Red Hat Enterprise Linux 8.4 Extended Update Support update for thunderbird
- Red Hat Enterprise Linux 8.2 Extended Update Support update for firefox
- Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions update for thunderbird
- Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions update for firefox
- Red Hat Enterprise Linux 9 update for thunderbird
- Red Hat Enterprise Linux 8.4 Extended Update Support update for firefox
- Red Hat Enterprise Linux 8 update for firefox
- Red Hat Enterprise Linux 8 update for thunderbird
- Red Hat Enterprise Linux 9 update for firefox
- Multiple vulnerabilities in OpenShift Container Platform 4.9
- Multiple vulnerabilities in OpenShift sandboxed containers
- Multiple vulnerabilities in Oracle Linux
- CentOS 7 update for expat
- Multiple vulnerabilities in Tenable Nessus
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP)
- Multiple vulnerabilities in IBM AIX
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.4
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.6
- Pale Moon update for libexpat
- Multiple vulnerabilities in Tenable Nessus
- Multiple vulnerabilities in Openshift Logging 5.3
- Multiple vulnerabilities in OpenShift Logging 5.5
- Multiple vulnerabilities in IBM QRadar Network Packet Capture
- Multiple vulnerabilities in Mozilla Firefox and Firefox ESR
- Ubuntu update for firefox
- Multiple vulnerabilities in Red Hat OpenShift Logging 5.4
- Ubuntu update for expat
- Cloud Foundry Foundation cflinuxfs3 update for libexpat
- Gentoo update for Mozilla Firefox
- Multiple vulnerabilities in Red Hat Virtualization 4 for RHEL 8
- Multiple vulnerabilties in Red Hat OpenShift Virtualization
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.1
- Multiple vulnerabilities in IBM MQ Operator
- Multiple vulnerabilities in OpenShift Virtualization 4.11
- Amazon Linux AMI update for expat
- Multiple vulnerabilities in IBM Db2 Net Search Extender
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- IBM Tivoli Monitoring update for expat
- Multiple vulnerabilities in Dell PowerScale OneFS
- Multiple vulnerabilities in Dell VxRail Appliance components
- Use-after-free in IBM Tivoli Network Manager (ITNM)
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Use-after-free in IBM Rational ClearCase
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM QRadar SIEM
- Ubuntu update for expat
- Multiple vulnerabilities in IBM Security Verify Bridge
- Use-after-free in HPE OneView
- Multiple vulnerabilities in API Gateway and API Manager
- Multiple vulnerabilities in Axway SecureTransport (October 2022)
- Use-after-free in IBM Cloud Pak System
- Use-after-free in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Siemens SCALANCE XCM332
- Multiple vulnerabilities in Nessus Network Monitor
- Multiple vulnerabilities in Siemens SINEC NMS
- Red Hat Enterprise Linux 8 update for mingw-expat
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in Oracle VM Server for x86
- Multiple vulnerabilities in Dell ECS
- Multiple vulnerabilities in IBM Security Guardium
- F5 BIG-IP and BIG-IQ Centralized Management update for libexpat
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Dell XtremIO X2
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in Service Telemetry Framework 1.5
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4
- Multiple vulnerabilities in Dell PowerScale OneFS
- Multiple vulnerabilities in IBM Netcool Operations Insight
- openEuler update for expat
- openEuler update for firefox
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in Dell Data Lakehouse System Software
- Amazon Linux AMI update for expat
- Multiple vulnerabilities in HPE Moonshot 1500 Chassis Manager
- Fedora 36 update for expat
- Fedora 35 update for expat
- Fedora 36 update for mingw-expat
- Fedora 35 update for mingw-expat
- Fedora 37 update for mingw-expat
- Anolis OS update for expat
- Anolis OS update for expat
- Anolis OS update for firefox
- Anolis OS update for thunderbird
- Anolis OS update for thunderbird
- Anolis OS update for firefox
- Anolis OS update for mingw-expat
- RSA Authentication Manager update for third-party components
- Dell NetWorker Management Console update for third-party components
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in IBM Storage Defender - Data Protect