CVE-2022-23852

NameCVE-2022-23852
DescriptionExpat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2904-1, DLA-2935-1, DSA-5073-1, ELA-556-1, ELA-574-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
expat (PTS)jessie, jessie (lts)2.1.0-6+deb8u12fixed
stretch (security)2.2.0-2+deb9u5fixed
stretch (lts), stretch2.2.0-2+deb9u9fixed
buster, buster (lts)2.2.6-2+deb10u8fixed
buster (security)2.2.6-2+deb10u7fixed
bullseye2.2.10-2+deb11u5fixed
bullseye (security)2.2.10-2+deb11u6fixed
bookworm (security), bookworm2.5.0-1+deb12u1fixed
sid, trixie2.6.4-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
expatsourcejessie2.1.0-6+deb8u8ELA-574-1
expatsourcestretch2.2.0-2+deb9u5DLA-2935-1
expatsourcebuster2.2.6-2+deb10u2DSA-5073-1
expatsourcebullseye2.2.10-2+deb11u1DSA-5073-1
expatsource(unstable)2.4.3-2

Notes

https://github.com/libexpat/libexpat/pull/550
Fixed by: https://github.com/libexpat/libexpat/commit/847a645152f5ebc10ac63b74b604d0c1a79fae40 (R_2_4_4)
Tests: https://github.com/libexpat/libexpat/commit/acf956f14bf79a5e6383a969aaffec98bfbc2e44

Search for package or bug name: Reporting problems