CVE-2022-40674: libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c. And apparent reproducer: https://github.com/libexpat/libexpat/pull/640
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=aacaf722fc8bc0f7cc113a5fe01fea450f044258 commit aacaf722fc8bc0f7cc113a5fe01fea450f044258 Author: Sebastian Pipping <sping@gentoo.org> AuthorDate: 2022-09-20 15:40:07 +0000 Commit: Sebastian Pipping <sping@gentoo.org> CommitDate: 2022-09-20 15:41:31 +0000 dev-libs/expat: 2.4.9 + EAPI 8 Bug: https://bugs.gentoo.org/870097 Signed-off-by: Sebastian Pipping <sping@gentoo.org> dev-libs/expat/Manifest | 1 + dev-libs/expat/expat-2.4.9.ebuild | 94 +++++++++++++++++++++++++++++++++++++++ 2 files changed, 95 insertions(+)
Please stabilize when ready.
cleanup done.
GLSA request filed
Thanks!
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=03f0a34b2dd087d0388307c6a72febd44202bb20 commit 03f0a34b2dd087d0388307c6a72febd44202bb20 Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2022-09-29 14:24:39 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2022-09-29 14:48:02 +0000 [ GLSA 202209-24 ] Expat: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/791703 Bug: https://bugs.gentoo.org/830422 Bug: https://bugs.gentoo.org/831918 Bug: https://bugs.gentoo.org/833431 Bug: https://bugs.gentoo.org/870097 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: John Helmert III <ajak@gentoo.org> glsa-202209-24.xml | 61 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 61 insertions(+)
GLSA released, all done!