CVE-2022-25313

Updated: 2026-02-27 01:15:24.951931

Description:

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 4.3
CVSS Version 3.x MEDIUM 6.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 6 ELS expat 2.0.1 6.5 MEDIUM Ignored 2022-08-17 11:02:24 Ignored due to low severity score
CentOS 7 ELS expat 2.1.0 6.5 MEDIUM Ignored 2023-09-19 09:30:27 Ignored due to low severity
CentOS 8.4 ELS expat 2.2.5 6.5 MEDIUM Released CLSA-2022:1660757175 2022-08-17 14:02:23
CentOS 8.5 ELS expat 2.2.5 6.5 MEDIUM Released CLSA-2022:1660758476 2022-08-17 14:02:23
CloudLinux 6 ELS expat 2.0.1 6.5 MEDIUM Ignored 2022-08-17 11:02:24 Out of support scope
Debian 10 ELS expat 2.2.6 6.5 MEDIUM Ignored 2025-10-11 00:22:58 Ignored due to low severity
Oracle Linux 6 ELS expat 2.0.1 6.5 MEDIUM Ignored 2022-08-17 11:02:24 Ignored due to low severity score
Ubuntu 16.04 ELS expat 2.1.0 6.5 MEDIUM Released CLSA-2022:1660760528 2022-08-17 17:02:14
Ubuntu 18.04 ELS expat 2.2.5-3 6.5 MEDIUM Already Fixed 2023-06-02 09:09:54