Bug 2056366 (CVE-2022-25235)

Summary: CVE-2022-25235 expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution
Product: [Other] Security Response Reporter: Avinash Hanwate <ahanwate>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: abrt-devel-list, amaumene, bdettelb, caswilli, csutherl, erack, erik-fedora, fhrdina, fjansen, gzaronik, jburrell, jclere, jhorak, jkoehler, jorton, jwong, jwon, kaycoth, manisandro, michal.skrivanek, micjohns, mperina, mturk, nikhjain, nobody, ofalk, pjindal, psegedy, rcritten, rh-bugzilla, rh-spice-bugs, rjones, sthirugn, stransky, szappis, tcarlin, tfister, tkasparek, tkorbar, tpopela, tsasak, vkrizan, vkumar, vmugicag
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: expat 2.4.5 Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in expat. Passing malformed 2- and 3-byte UTF-8 sequences (for example, from start tag names) to the XML processing application on top of expat can lead to arbitrary code execution. This issue is dependent on how invalid UTF-8 is handled inside the XML processor.
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-12-04 00:17:41 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2056367, 2056368, 2057031, 2057032, 2057033, 2057034, 2057035, 2057036, 2057037, 2057090, 2057323, 2057324, 2057430, 2058088, 2058089, 2058090, 2058091, 2058092, 2058093, 2058094, 2058095, 2058096, 2058097, 2058098, 2058099, 2058100, 2058101, 2058102, 2058103, 2058104, 2058105, 2058106, 2058107, 2058108, 2058109, 2058110, 2058111, 2058112, 2058113, 2058114, 2058115, 2058116, 2058117, 2058349, 2058352, 2065579, 2065582, 2070469, 2070481, 2072092, 2072228    
Bug Blocks: 2056373    

Description Avinash Hanwate 2022-02-21 05:24:36 UTC
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
http://www.openwall.com/lists/oss-security/2022/02/19/1
https://github.com/libexpat/libexpat/pull/562

Comment 1 Avinash Hanwate 2022-02-21 05:25:07 UTC
Created expat tracking bugs for this issue:

Affects: fedora-all [bug 2056367]


Created mingw-expat tracking bugs for this issue:

Affects: fedora-all [bug 2056368]

Comment 2 Mauro Matteo Cascella 2022-02-22 15:25:08 UTC
Upstream commit:
https://github.com/libexpat/libexpat/commit/3f0a0cb644438d4d8e3294cd0b1245d0edb0c6c6

Comment 7 Mauro Matteo Cascella 2022-02-23 11:51:59 UTC
Created xmlrpc-c tracking bugs for this issue:

Affects: fedora-all [bug 2057430]

Comment 12 errata-xmlrpc 2022-03-10 15:06:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions

Via RHSA-2022:0815 https://access.redhat.com/errata/RHSA-2022:0815

Comment 13 errata-xmlrpc 2022-03-10 15:14:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Extended Update Support

Via RHSA-2022:0816 https://access.redhat.com/errata/RHSA-2022:0816

Comment 14 errata-xmlrpc 2022-03-10 15:18:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:0818 https://access.redhat.com/errata/RHSA-2022:0818

Comment 15 errata-xmlrpc 2022-03-10 15:24:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Extended Update Support

Via RHSA-2022:0817 https://access.redhat.com/errata/RHSA-2022:0817

Comment 16 errata-xmlrpc 2022-03-10 16:28:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2022:0824 https://access.redhat.com/errata/RHSA-2022:0824

Comment 17 errata-xmlrpc 2022-03-14 10:04:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Extended Update Support

Via RHSA-2022:0843 https://access.redhat.com/errata/RHSA-2022:0843

Comment 18 errata-xmlrpc 2022-03-14 10:07:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions

Via RHSA-2022:0847 https://access.redhat.com/errata/RHSA-2022:0847

Comment 19 errata-xmlrpc 2022-03-14 10:13:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:0845 https://access.redhat.com/errata/RHSA-2022:0845

Comment 20 errata-xmlrpc 2022-03-14 10:26:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Extended Update Support

Via RHSA-2022:0853 https://access.redhat.com/errata/RHSA-2022:0853

Comment 21 errata-xmlrpc 2022-03-14 10:44:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2022:0850 https://access.redhat.com/errata/RHSA-2022:0850

Comment 22 errata-xmlrpc 2022-03-16 16:17:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:0951 https://access.redhat.com/errata/RHSA-2022:0951

Comment 23 Sandro Bonazzola 2022-03-18 09:18:39 UTC
Created expat tracking bugs for this issue:

Affects: oVirt 4.4 [ bug 2065579 ]

Affects: CentOS Stream 8 [ bug 2065582 ]

Comment 24 errata-xmlrpc 2022-03-22 16:20:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Extended Update Support

Via RHSA-2022:1012 https://access.redhat.com/errata/RHSA-2022:1012

Comment 25 errata-xmlrpc 2022-03-24 13:30:48 UTC
This issue has been addressed in the following products:

  Red Hat Virtualization 4 for Red Hat Enterprise Linux 8

Via RHSA-2022:1053 https://access.redhat.com/errata/RHSA-2022:1053

Comment 28 errata-xmlrpc 2022-03-28 08:56:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions

Via RHSA-2022:1068 https://access.redhat.com/errata/RHSA-2022:1068

Comment 30 errata-xmlrpc 2022-03-28 09:43:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Extended Update Support

Via RHSA-2022:1070 https://access.redhat.com/errata/RHSA-2022:1070

Comment 31 errata-xmlrpc 2022-03-28 11:49:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2022:1069 https://access.redhat.com/errata/RHSA-2022:1069

Comment 33 errata-xmlrpc 2022-04-07 09:03:36 UTC
This issue has been addressed in the following products:

  Red Hat Virtualization 4 for Red Hat Enterprise Linux 7

Via RHSA-2022:1263 https://access.redhat.com/errata/RHSA-2022:1263

Comment 34 errata-xmlrpc 2022-04-12 15:45:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6 Extended Lifecycle Support

Via RHSA-2022:1309 https://access.redhat.com/errata/RHSA-2022:1309

Comment 35 errata-xmlrpc 2022-04-26 10:18:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions

Via RHSA-2022:1539 https://access.redhat.com/errata/RHSA-2022:1539

Comment 36 errata-xmlrpc 2022-04-26 11:11:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Extended Update Support

Via RHSA-2022:1540 https://access.redhat.com/errata/RHSA-2022:1540

Comment 37 errata-xmlrpc 2022-04-28 16:15:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Extended Update Support

Via RHSA-2022:1644 https://access.redhat.com/errata/RHSA-2022:1644

Comment 38 errata-xmlrpc 2022-04-28 16:37:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:1643 https://access.redhat.com/errata/RHSA-2022:1643

Comment 39 errata-xmlrpc 2022-10-26 20:08:26 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Core Services

Via RHSA-2022:7144 https://access.redhat.com/errata/RHSA-2022:7144

Comment 40 errata-xmlrpc 2022-10-26 20:21:57 UTC
This issue has been addressed in the following products:

  JBoss Core Services on RHEL 7
  JBoss Core Services for RHEL 8

Via RHSA-2022:7143 https://access.redhat.com/errata/RHSA-2022:7143

Comment 42 errata-xmlrpc 2022-11-08 10:34:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:7811 https://access.redhat.com/errata/RHSA-2022:7811

Comment 43 Product Security DevOps Team 2022-12-04 00:17:35 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-25235