Oracle Linux Security Advisory ELSA-2022-6878 https://linux.oracle.com/errata/ELSA-2022-6878.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: expat-2.2.5-8.0.1.el8_6.3.i686.rpm expat-2.2.5-8.0.1.el8_6.3.x86_64.rpm expat-devel-2.2.5-8.0.1.el8_6.3.i686.rpm expat-devel-2.2.5-8.0.1.el8_6.3.x86_64.rpm aarch64: expat-2.2.5-8.0.1.el8_6.3.aarch64.rpm expat-devel-2.2.5-8.0.1.el8_6.3.aarch64.rpm SRPMS: https://oss.oracle.com/ol8/SRPMS-updates/expat-2.2.5-8.0.1.el8_6.3.src.rpm Related CVEs: CVE-2022-40674 Description of changes: [2.2.5-8.0.1.3] - lib: Prevent integer overflow in doProlog [CVE-2022-23990][Orabug: 33910314] [2.2.5-8.3] - Ensure raw tagnames are safe exiting internalEntityParser - Resolves: CVE-2022-40674 _______________________________________________ El-errata mailing list [email protected] https://oss.oracle.com/mailman/listinfo/el-errata