Description
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3172-1 | libxml2 security update |
Debian DSA |
DSA-5271-1 | libxml2 security update |
EUVD |
EUVD-2022-43601 | An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked. |
Ubuntu USN |
USN-5760-1 | libxml2 vulnerabilities |
Ubuntu USN |
USN-5760-2 | libxml2 vulnerabilities |
References
History
Mon, 28 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Apple
Subscribe
Ipados
Subscribe
Iphone Os
Subscribe
Macos
Subscribe
Tvos
Subscribe
Watchos
Subscribe
Netapp
Subscribe
Active Iq Unified Manager
Subscribe
Clustered Data Ontap
Subscribe
Clustered Data Ontap Antivirus Connector
Subscribe
H300s
Subscribe
H300s Firmware
Subscribe
H410c
Subscribe
H410c Firmware
Subscribe
H410s
Subscribe
H410s Firmware
Subscribe
H500s
Subscribe
H500s Firmware
Subscribe
H700s
Subscribe
H700s Firmware
Subscribe
Manageability Software Development Kit
Subscribe
Smi-s Provider
Subscribe
Snapmanager
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Jboss Core Services
Subscribe
Rhel Eus
Subscribe
Xmlsoft
Subscribe
Libxml2
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-28T19:49:17.691Z
Reserved: 2022-09-09T00:00:00.000Z
Link: CVE-2022-40304
Updated: 2024-08-03T12:14:40.052Z
Status : Modified
Published: 2022-11-23T18:15:12.167
Modified: 2025-04-28T20:15:19.607
Link: CVE-2022-40304
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN