In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
https://www.debian.org/security/2022/dsa-5266
https://security.netapp.com/advisory/ntap-20221118-0007/
https://security.gentoo.org/glsa/202210-38
https://lists.debian.org/debian-lts-announce/2022/10/msg00033.html
https://github.com/libexpat/libexpat/pull/650
https://github.com/libexpat/libexpat/pull/616
https://github.com/libexpat/libexpat/issues/649