xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context. (CVE-2022-25235)
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2022-0183.json"