There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2653-1 | libxml2 security update |
EUVD |
EUVD-2022-4443 | There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application. |
Github GHSA |
GHSA-jw9f-hh49-cvp9 | Nokogiri contains libxml Out-of-bounds Write vulnerability |
Ubuntu USN |
USN-4991-1 | libxml2 vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 02 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-125 | |
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-12-02T21:34:00.585Z
Reserved: 2021-04-27T00:00:00.000Z
Link: CVE-2021-3517
Updated: 2024-08-03T16:53:17.731Z
Status : Modified
Published: 2021-05-19T14:15:07.553
Modified: 2025-12-02T22:16:07.097
Link: CVE-2021-3517
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN