Skip to content

libexpat CVE-2022-25315

High
webern published GHSA-grm4-6gc8-2424 Mar 30, 2022

Package

libexpat (bottlerocket)

Affected versions

<1.7.0

Patched versions

1.7.0

Description

Description

An integer overflow was found in expat. The issue occurs in storeRawNames() by abusing the m_buffer expansion logic to allow allocations very close to INT_MAX and out-of-bounds heap writes. This flaw can cause a denial of service or potentially arbitrary code execution.

Severity

High

CVE ID

CVE-2022-25315

Weaknesses

No CWEs