Use-after-free in Libxml2 - CVE-2022-49043
Published: February 3, 2025 / Updated: March 12, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the xmlXIncludeAddNode() function in xinclude.c. A remote attacker can pass specially crafted XML input to the application, trigger a use-after-free error and crash the application or potentially execute arbitrary code.
Affected software
PowerStore 7000T
PowerStore 9000T
PowerStore 500T
PowerStore 9200T
PowerStore 1000T
PowerStore 1200T
PowerStore 3000T
PowerStore 3200Q
PowerStore 3200T
PowerStore 5000T
PowerStore 5200T
PowerStoreT OS
Debian Linux
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Ubuntu
Python 3 Module
Basesystem Module
openSUSE Leap
openEuler
IBM Concert Software
IBM Observability with Instana
Netcool Operations Insight
IBM Cloud Pak for Security
IBM Cloud Pak for Business Automation
Multicluster GlobalHub
Red Hat Advanced Cluster Management for Kubernetes
APEX Cloud Platform for Red Hat OpenShift
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
QRadar Suite
Juniper Secure Analytics (JSA)
Financial Transaction Manager
IBM Qradar SIEM
Guardium Data Security Center (GDSC)
Business Automation Insights
APEX Cloud Platform for Microsoft Azure
IBM MQ Appliance
SmartFabric OS10
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libxml2 (Ubuntu package)
libxml2-doc
libxml2-2-debuginfo-32bit
libxml2-2-32bit
libxml2-2-debuginfo
libxml2-tools-debuginfo
python-libxml2-debugsource
libxml2-devel
python-libxml2
libxml2-debugsource
python-libxml2-debuginfo
libxml2-tools
libxml2-2
libxml2 (Red Hat package)
libxml2
python3-libxml2
python-libxml2-python-debugsource
python3-libxml2-python
python3-libxml2-python-debuginfo
libxml2-2-32bit-debuginfo
libxml2-help
python2-libxml2
libxml2-debuginfo
libxml2 (Debian package)
libxml2-devel-32bit
libxml2-2-64bit-debuginfo
libxml2-2-64bit
libxml2-devel-64bit
python311-libxml2-debuginfo
python311-libxml2
python3-libxml2-debuginfo
libxml2-python-debugsource
IBM API Connect
SmartFabric Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Virtualization
Red Hat OpenShift Container Platform
IBM CICS TX Advanced
IBM CICS TX Standard
How to mitigate CVE-2022-49043
IBM Concert Software - update to 1.1.0
IBM Observability with Instana - update to 1.0.297
Netcool Operations Insight - update to 1.6.15
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
Financial Transaction Manager - addressed in versions 3.2.13 iFix4, 4.0.6.0 iFix5, 4.0.7.0
Guardium Data Security Center (GDSC) - update to 3.8.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 11 IF03
IBM API Connect - update to 10.0.8.5
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
libxml2 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.9.10+dfsg-5ubuntu0.20.04.8, 2.9.10+dfsg-5ubuntu0.20.04.9, 2.9.13+dfsg-1ubuntu0.5, 2.9.13+dfsg-1ubuntu0.6, 2.9.14+dfsg-1.3ubuntu3.1, 2.9.14+dfsg-1.3ubuntu3.2, 2.12.7+dfsg-3ubuntu0.2
Multicluster GlobalHub - update to 1.2.2
SmartFabric Manager - update to 1.3.0
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
libxml2-doc - addressed in versions 2.9.4-46.78.1, 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
libxml2-2-debuginfo-32bit - update to 2.9.4-46.78.1
libxml2-2-32bit - addressed in versions 2.9.4-46.78.1, 2.9.7-150000.3.73.1, 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
libxml2-2-debuginfo - addressed in versions 2.9.4-46.78.1, 2.9.7-150000.3.73.1, 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
libxml2-tools-debuginfo - addressed in versions 2.9.4-46.78.1, 2.9.7-150000.3.73.1, 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
python-libxml2-debugsource - update to 2.9.4-46.78.1
libxml2-devel - addressed in versions 2.9.4-46.78.1, 2.9.7-150000.3.73.1, 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
python-libxml2 - update to 2.9.4-46.78.1
libxml2-debugsource - addressed in versions 2.9.4-46.78.1, 2.9.7-150000.3.73.1, 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
python-libxml2-debuginfo - update to 2.9.4-46.78.1
libxml2-tools - addressed in versions 2.9.4-46.78.1, 2.9.7-150000.3.73.1, 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
libxml2-2 - addressed in versions 2.9.4-46.78.1, 2.9.7-150000.3.73.1, 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
libxml2 (Red Hat package) - addressed in versions 2.9.7-16.el8_8.7, 2.9.7-18.el8_10.2, 2.9.13-3.el9_2.4, 2.9.13-6.el9_5.1, 2.9.13-9.el9_4
libxml2 - update to 2.9.7-18.0.4
libxml2-devel - update to 2.9.7-18.0.4
python3-libxml2 - update to 2.9.7-18.0.4
python-libxml2-python-debugsource - update to 2.9.7-150000.3.73.1
python3-libxml2-python - update to 2.9.7-150000.3.73.1
python3-libxml2-python-debuginfo - update to 2.9.7-150000.3.73.1
libxml2-2-32bit-debuginfo - addressed in versions 2.9.7-150000.3.73.1, 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
libxml2-help - update to 2.9.10-42
python3-libxml2 - update to 2.9.10-42
python2-libxml2 - update to 2.9.10-42
libxml2-devel - update to 2.9.10-42
libxml2-debugsource - update to 2.9.10-42
libxml2-debuginfo - update to 2.9.10-42
libxml2 - update to 2.9.10-42
libxml2 (Debian package) - update to 2.9.14+dfsg-1.3~deb12u2
libxml2-devel-32bit - addressed in versions 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
libxml2-2-64bit-debuginfo - addressed in versions 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
libxml2-2-64bit - addressed in versions 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
libxml2-devel-64bit - addressed in versions 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
python311-libxml2-debuginfo - addressed in versions 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
python311-libxml2 - addressed in versions 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
python3-libxml2 - addressed in versions 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
python3-libxml2-debuginfo - addressed in versions 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
libxml2-python-debugsource - addressed in versions 2.9.14-150400.5.35.1, 2.10.3-150500.5.20.1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.11.7, 2.12.3
APEX Cloud Platform for Red Hat OpenShift - addressed in versions 03.01.02.00, 03.02.04.00
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4
PowerStoreT OS - update to 4.0.1.3-2494147
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.5.7, 4.6.0, 4.6.3
Red Hat OpenShift Container Platform - addressed in versions 4.12.76, 4.13.58, 4.14.52, 4.15.50, 4.16.38, 4.16.39, 4.16.44, 4.17.22, 4.17.25, 4.18.6, 4.18.9
OpenShift Virtualization - addressed in versions 4.15.9, 4.16.7
OpenShift Logging - addressed in versions 5.8.18, 5.9.12, 6.0.6, 6.1.4, 6.1.5
Juniper Secure Analytics (JSA) - update to 7.5.0 UP11 IF03
IBM MQ Appliance - addressed in versions 9.3.0.28, 9.4.0.11, 9.4.2.1
IBM CICS TX Advanced - update to 10.1.0.0 ifix37
SmartFabric OS10 - addressed in versions 10.5.4.15, 10.5.5.14, 10.5.6.9
IBM CICS TX Standard - update to 11.1.0.0 ifix30
External References
Related Security Bulletins
- Use-after-free in libxml2
- Ubuntu update for libxml2
- SUSE update for libxml2
- SUSE update for libxml2
- SUSE update for libxml2
- SUSE update for libxml2
- Red Hat Enterprise Linux 9 update for libxml2
- openEuler 20.03 LTS SP4 update for libxml2
- Red Hat Enterprise Linux 9 update for libxml2
- Red Hat Enterprise Linux 8 update for libxml2
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Ubuntu update for libxml2
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.5
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in OpenShift Logging 5.9
- Multiple vulnerabilities in OpenShift Logging 5.8
- Red Hat Enterprise Linux 8 update for libxml2
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.6
- Multiple vulnerabilities in OpenShift Virtualization 4.15
- Red Hat Enterprise Linux 9 update for libxml2
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.6
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in OpenShift Logging 6.0
- Multiple vulnerabilities in OpenShift Logging 6.1
- Anolis OS update for libxml2
- Multiple vulnerabilities in Multicluster GlobalHub 1.2
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in OpenShift Logging 6.1
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in OpenShift Virtualization 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM CICS TX Standard
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- IBM MQ Appliance update for libxml2
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.11
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Juniper Secure Analytics update for third-party components
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Dell SmartFabric OS10
- Dell SmartFabric OS10 update for third-party components
- Multiple vulnerabilities in Dell APEX Cloud Platform for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Dell Networking OS10 update for third-party components
- Multiple vulnerabilities in Dell PowerStoreT OS
- Multiple vulnerabilities in IBM Cloud Pak for Security and IBM QRadar Suite Software
- Multiple vulnerabilities in IBM Concert Software
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in IBM Financial Transaction Manager (FTM) for RedHat OpenShift
- Dell SmartFabric Manager update for third-party components
- Debian update for libxml2
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation