An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apple
Subscribe
|
|
|
Netapp
Subscribe
|
Active Iq Unified Manager
Subscribe
Clustered Data Ontap
Subscribe
Clustered Data Ontap Antivirus Connector
Subscribe
H300s
Subscribe
H300s Firmware
Subscribe
H410c
Subscribe
H410c Firmware
Subscribe
H410s
Subscribe
H410s Firmware
Subscribe
H500s
Subscribe
H500s Firmware
Subscribe
H700s
Subscribe
H700s Firmware
Subscribe
Manageability Software Development Kit
Subscribe
Smi-s Provider
Subscribe
Snapmanager
Subscribe
|
|
Redhat
Subscribe
|
|
|
Xmlsoft
Subscribe
|
Libxml2
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3172-1 | libxml2 security update |
Debian DSA |
DSA-5271-1 | libxml2 security update |
EUVD |
EUVD-2022-43601 | An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked. |
Ubuntu USN |
USN-5760-1 | libxml2 vulnerabilities |
Ubuntu USN |
USN-5760-2 | libxml2 vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 28 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-28T19:49:17.691Z
Reserved: 2022-09-09T00:00:00.000Z
Link: CVE-2022-40304
Updated: 2024-08-03T12:14:40.052Z
Status : Modified
Published: 2022-11-23T18:15:12.167
Modified: 2025-04-28T20:15:19.607
Link: CVE-2022-40304
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN