CVE-2022-25313: Debian Linux

Medium severity, CVSS 6.5. EPSS: 3.3% chance of exploitation in the next 30 days.

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

Affected products

  • Debian Debian Linux: version 10.0 only; version 11.0 only
  • Fedoraproject Fedora: version 34 only; version 35 only
  • Libexpat Project Libexpat: before 2.4.5 (fixed in 2.4.5)
  • Oracle HTTP Server: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle ZFS Storage Appliance Kit: version 8.8 only
  • Siemens Sinema Remote Connect Server: before 3.1 (fixed in 3.1)

Published 2022-02-18. Last modified 2026-06-17.