CVE-2022-25313: Debian Linux
Medium severity, CVSS 6.5. EPSS: 3.3% chance of exploitation in the next 30 days.
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
Affected products
- Debian Debian Linux: version 10.0 only; version 11.0 only
- Fedoraproject Fedora: version 34 only; version 35 only
- Libexpat Project Libexpat: before 2.4.5 (fixed in 2.4.5)
- Oracle HTTP Server: version 12.2.1.3.0 only; version 12.2.1.4.0 only
- Oracle ZFS Storage Appliance Kit: version 8.8 only
- Siemens Sinema Remote Connect Server: before 3.1 (fixed in 3.1)
Published 2022-02-18. Last modified 2026-06-17.