valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

Project Subscriptions

Vendors Products
Debian Linux Subscribe
Fedoraproject Subscribe
Active Iq Unified Manager Subscribe
Bootstrap Os Subscribe
Clustered Data Ontap Subscribe
Clustered Data Ontap Antivirus Connector Subscribe
H300e Firmware Subscribe
H300s Firmware Subscribe
H410c Firmware Subscribe
H410s Firmware Subscribe
H500e Firmware Subscribe
H500s Firmware Subscribe
H700e Firmware Subscribe
H700s Firmware Subscribe
Hci Compute Node Subscribe
Manageability Software Development Kit Subscribe
Ontap Select Deploy Administration Utility Subscribe
Smi-s Provider Subscribe
Snapdrive Subscribe
Snapmanager Subscribe
Solidfire\, Enterprise Sds \& Hci Storage Node Subscribe
Solidfire \& Hci Management Node Subscribe
Communications Cloud Native Core Binding Support Function Subscribe
Communications Cloud Native Core Network Function Cloud Native Environment Subscribe
Communications Cloud Native Core Network Repository Function Subscribe
Communications Cloud Native Core Network Slice Selection Function Subscribe
Communications Cloud Native Core Unified Data Repository Subscribe
Mysql Workbench Subscribe
Zfs Storage Appliance Kit Subscribe
Enterprise Linux Subscribe
Jboss Core Services Subscribe
Xmlsoft Subscribe
Libxml2 Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2972-1 libxml2 security update
EUVD EUVD EUVD-2022-28391 valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
Ubuntu USN Ubuntu USN USN-5324-1 libxml2 vulnerability
Ubuntu USN Ubuntu USN USN-5422-1 libxml2 vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-05-05T16:26:56.501Z

Reserved: 2022-01-17T00:00:00.000Z

Link: CVE-2022-23308

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-02-26T05:15:08.280

Modified: 2025-05-05T17:17:56.523

Link: CVE-2022-23308

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-02-20T00:00:00Z

Links: CVE-2022-23308 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses