CVE-2022-25314

Updated: 2026-02-27 03:07:15.221245

Description:

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 5.0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 6 ELS expat 2.0.1 7.5 HIGH Not Vulnerable 2022-08-17 11:02:28 Not affected: This CVE targets an integer overflow in Expat’s copyString helper (fixed in 2.4.5); ...
CentOS 7 ELS expat 2.1.0 7.5 HIGH Not Vulnerable 2023-09-19 09:30:27 Not affected: The vulnerable code path (copyString) is only invoked for the parser’s encoding-name...
CentOS 8.4 ELS expat 2.2.5 7.5 HIGH Released CLSA-2022:1660757175 2022-08-17 14:02:28
CentOS 8.5 ELS expat 2.2.5 7.5 HIGH Released CLSA-2022:1660758476 2022-08-17 14:02:28
CloudLinux 6 ELS expat 2.0.1 7.5 HIGH Not Vulnerable 2022-08-17 11:02:28
Debian 10 ELS expat 2.2.6 7.5 HIGH Already Fixed 2025-11-03 17:22:21
Oracle Linux 6 ELS expat 2.0.1 7.5 HIGH Not Vulnerable 2022-08-17 11:02:27 Not affected: This CVE targets an integer overflow in Expat’s copyString helper (fixed in 2.4.5); ...
Ubuntu 16.04 ELS expat 2.1.0 7.5 HIGH Not Vulnerable 2022-08-16 03:01:13 Not affected: The vulnerable code path (copyString) is only invoked for the parser’s encoding-name...
Ubuntu 18.04 ELS expat 2.2.5-3 7.5 HIGH Already Fixed 2023-06-02 09:09:54