Description
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2653-1 | libxml2 security update |
EUVD |
EUVD-2022-4443 | There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application. |
Github GHSA |
GHSA-jw9f-hh49-cvp9 | Nokogiri contains libxml Out-of-bounds Write vulnerability |
Ubuntu USN |
USN-4991-1 | libxml2 vulnerabilities |
References
History
Tue, 02 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-125 | |
| Metrics |
ssvc
|
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Netapp
Subscribe
Active Iq Unified Manager
Subscribe
Clustered Data Ontap
Subscribe
Clustered Data Ontap Antivirus Connector
Subscribe
E-series Santricity Os Controller
Subscribe
E-series Santricity Storage Manager
Subscribe
E-series Santricity Web Services
Subscribe
Hci H410c
Subscribe
Hci H410c Firmware
Subscribe
Hci Management Node
Subscribe
Manageability Software Development Kit
Subscribe
Oncommand Insight
Subscribe
Oncommand Workflow Automation
Subscribe
Ontap Select Deploy Administration Utility
Subscribe
Santricity Unified Manager
Subscribe
Snapdrive
Subscribe
Snapmanager
Subscribe
Solidfire
Subscribe
Oracle
Subscribe
Communications Cloud Native Core Network Function Cloud Native Environment
Subscribe
Enterprise Manager Base Platform
Subscribe
Mysql Workbench
Subscribe
Openjdk
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Real User Experience Insight
Subscribe
Zfs Storage Appliance Kit
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Jboss Core Services
Subscribe
Rhmt
Subscribe
Xmlsoft
Subscribe
Libxml2
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-12-02T21:34:00.585Z
Reserved: 2021-04-27T00:00:00.000Z
Link: CVE-2021-3517
Updated: 2024-08-03T16:53:17.731Z
Status : Modified
Published: 2021-05-19T14:15:07.553
Modified: 2025-12-02T22:16:07.097
Link: CVE-2021-3517
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN