El-errata: ELSA-2022-0951 Important: Oracle Linux 8 expat security update
Oracle Linux Security Advisory ELSA-2022-0951
http://linux.oracle.com/errata/ELSA-2022-0951.html
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
x86_64:
expat-2.2.5-4.el8_5.3.i686.rpm
expat-2.2.5-4.el8_5.3.x86_64.rpm
expat-devel-2.2.5-4.el8_5.3.i686.rpm
expat-devel-2.2.5-4.el8_5.3.x86_64.rpm
aarch64:
expat-2.2.5-4.el8_5.3.aarch64.rpm
expat-devel-2.2.5-4.el8_5.3.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/expat-2.2.5-4.el8_5.3.src.rpm
Related CVEs:
CVE-2021-45960
CVE-2021-46143
CVE-2022-22822
CVE-2022-22823
CVE-2022-22824
CVE-2022-22825
CVE-2022-22826
CVE-2022-22827
CVE-2022-23852
CVE-2022-25235
CVE-2022-25236
CVE-2022-25315
Description of changes:
[2.2.5-4.3]
- Improve fix for CVE-2022-25236
- Related: CVE-2022-25236
[2.2.5-4.2]
- Fix multiple CVEs
- Resolves: CVE-2022-25236
- Resolves: CVE-2022-25235
- Resolves: CVE-2022-25315
[2.2.5-4.1]
- Fix multiple CVEs
- CVE-2022-23852 expat: integer overflow in function XML_GetBuffer
- CVE-2021-45960 expat: Large number of prefixed XML attributes on a single tag can crash libexpat
- CVE-2021-46143 expat: Integer overflow in doProlog in xmlparse.c
- CVE-2022-22827 Integer overflow in storeAtts in xmlparse.c
- CVE-2022-22826 Integer overflow in nextScaffoldPart in xmlparse.c
- CVE-2022-22825 Integer overflow in lookup in xmlparse.c
- CVE-2022-22824 Integer overflow in defineAttribute in xmlparse.c
- CVE-2022-22823 Integer overflow in build_model in xmlparse.c
- CVE-2022-22822 Integer overflow in addBinding in xmlparse.c
- Resolves: CVE-2022-23852
- Resolves: CVE-2021-45960
- Resolves: CVE-2021-46143
- Resolves: CVE-2022-22827
- Resolves: CVE-2022-22826
- Resolves: CVE-2022-22825
- Resolves: CVE-2022-22824
- Resolves: CVE-2022-22823
- Resolves: CVE-2022-22822
_______________________________________________
An expat security update has been released for Oracle Linux 8.