<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE2-SA-2023-0107</id>
    <title>An update for squashfs-tools is now available for HCE 2.0</title>
    <severity>Important</severity>
    <release>HCE 2.0</release>
    <issued date="2023-01-05 20:19:38"/>
    <updated date="2023-01-05 20:19:38"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2022-40153" id="CVE-2022-40153" title="CVE-2022-40153 Base Score: 7.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2021-40153" id="CVE-2021-40153" title="CVE-2021-40153 Base Score: 8.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2022-41053" id="CVE-2022-41053" title="CVE-2022-41053 Base Score: 7.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" type="cve"/>
    </references>
    <description>Security Fix(es):

Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack. (CVE-2022-40153)

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination. (CVE-2021-40153)

Windows Kerberos Denial of Service Vulnerability. (CVE-2022-41053)
</description>
    <pkglist>
      <collection short="HCE 2.0" package="squashfs-tools">
        <name>HCE 2.0</name>
        <package arch="aarch64" name="squashfs-tools" version="4.5" release="1.r2.hce2">
          <filename>squashfs-tools-4.5-1.r2.hce2.aarch64.rpm</filename>
        </package>
        <package arch="x86_64" name="squashfs-tools" version="4.5" release="1.r2.hce2">
          <filename>squashfs-tools-4.5-1.r2.hce2.x86_64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
