CVE-2025-22872

Public on 2025-04-16
Modified on 2025-06-02
Description
The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content following such tags as being placed in the wrong scope during DOM construction, but only when tags are in foreign content (e.g. , , etc contexts).

After analysis, we have determined that 2025-22872 do not pose a security risk to docker or containerd on HAQM Linux 2 or HAQM Linux 2023. Source code analysis using govulncheck has confirmed that these packages do not contain the vulnerable code. As a result, no security patches are required for these specific packages on AL2 and AL2023.
Severity
Medium severity
Medium
CVSS v3 Base Score
6.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 2 - Core amazon-cloudwatch-agent Pending Fix
HAQM Linux 2023 amazon-cloudwatch-agent Pending Fix
HAQM Linux 2 - Aws-nitro-enclaves-cli Extra amazon-ecr-credential-helper Not Affected
HAQM Linux 2 - Docker Extra amazon-ecr-credential-helper Not Affected
HAQM Linux 2 - Ecs Extra amazon-ecr-credential-helper Not Affected
HAQM Linux 2023 amazon-ecr-credential-helper Not Affected
HAQM Linux 1 amazon-ssm-agent No Fix Planned
HAQM Linux 2 - Core amazon-ssm-agent Not Affected
HAQM Linux 2023 amazon-ssm-agent Not Affected
HAQM Linux 2 - Core cni-plugins Not Affected
HAQM Linux 2023 cni-plugins Not Affected
HAQM Linux 1 containerd No Fix Planned
HAQM Linux 2 - Aws-nitro-enclaves-cli Extra containerd Not Affected
HAQM Linux 2 - Docker Extra containerd Not Affected
HAQM Linux 2 - Ecs Extra containerd Not Affected
HAQM Linux 2023 containerd Not Affected
HAQM Linux 2 - Core cri-tools Pending Fix
HAQM Linux 1 docker No Fix Planned
HAQM Linux 2 - Aws-nitro-enclaves-cli Extra docker Not Affected
HAQM Linux 2 - Docker Extra docker Not Affected
HAQM Linux 2 - Ecs Extra docker Not Affected
HAQM Linux 2023 docker Not Affected
HAQM Linux 2 - Ecs Extra ecs-init Pending Fix
HAQM Linux 2023 ecs-init Pending Fix
HAQM Linux 1 golang No Fix Planned
HAQM Linux 2 - Core golang Not Affected
HAQM Linux 2023 golang Pending Fix
HAQM Linux 2 - Core golang-github-cpuguy83-go-md2man Not Affected
HAQM Linux 2 - Core golist Not Affected
HAQM Linux 2023 libcap Not Affected
HAQM Linux 2 - Core nerdctl 2025-05-21 ALAS2-2025-2863 Fixed
HAQM Linux 2023 nerdctl 2025-05-21 ALAS2023-2025-980 Fixed
HAQM Linux 2 - Aws-nitro-enclaves-cli Extra oci-add-hooks Not Affected
HAQM Linux 2 - Docker Extra oci-add-hooks Not Affected
HAQM Linux 2 - Ecs Extra oci-add-hooks Not Affected
HAQM Linux 2023 oci-add-hooks Not Affected
HAQM Linux 1 runc No Fix Planned
HAQM Linux 2 - Aws-nitro-enclaves-cli Extra runc Not Affected
HAQM Linux 2 - Docker Extra runc Not Affected
HAQM Linux 2 - Ecs Extra runc Not Affected
HAQM Linux 2023 runc Not Affected
HAQM Linux 2 - Docker Extra runfinch-finch 2025-05-21 ALAS2DOCKER-2025-063 Fixed
HAQM Linux 2023 runfinch-finch 2025-05-21 ALAS2023-2025-979 Fixed
HAQM Linux 2 - Docker Extra soci-snapshotter 2025-05-21 ALAS2DOCKER-2025-064 Fixed
HAQM Linux 2023 soci-snapshotter 2025-05-21 ALAS2023-2025-981 Fixed

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
NVD CVSSv3 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L