Use-after-free in Libxml2 - CVE-2022-23308

 

Use-after-free in Libxml2 - CVE-2022-23308

Published: March 1, 2022


Vulnerability identifier: #VU60922
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23308
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when processing ID and IDREF attributes in valid.c. A remote attacker can pass specially crafted XML input to the application, trigger a use-after-free error and crash the application or execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Libxml2
Gentoo Linux
Amazon Linux AMI
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
Anolis OS
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
watchOS
macOS
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Slackware Linux
Ubuntu
Apple iOS
iPadOS
tvOS
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
openEuler
Fedora
Chrome OS
SINAMICS GL150
SINAMICS PERFECT HARMONY GH180 6SR5
SINAMICS SL150
SCALANCE S615
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
libxml2-debuginfo
libxml2
libxml2-debugsource
libxml2-python-debuginfo
libxml2-python-debugsource
libxml2-32bit
libxml2-python
libxml2-doc
libxml2 (Ubuntu package)
libxml2-utils (Ubuntu package)
libxml2-tools-debuginfo
libxml2-2
libxml2-2-32bit
libxml2-2-debuginfo
libxml2-devel
python-libxml2-debugsource
libxml2-2-debuginfo-32bit
libxml2-tools
python-libxml2-debuginfo
python-libxml2
python3-libxml2-python-debuginfo
python3-libxml2-python
python-libxml2-python-debugsource
libxml2 (Red Hat package)
python3-libxml2
libxml2-help
python2-libxml2
python3-libxml2-debuginfo
libxml2-devel-32bit
libxml2-2-32bit-debuginfo
dev-libs/libxml2
cflinuxfs3
IBM Watson Machine Learning Accelerator
Red Hat OpenShift GitOps
IBM Integrated Analytics System
Harbor
Red Hat OpenShift Serverless
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Object Storage Systems
Dell Secure Connect Gateway
Tenable Nessus
Oracle Communications Cloud Native Core Network Repository Function
Oracle Communications Cloud Native Core Binding Support Function
Netcool Operations Insight
PowerProtect Data Domain
JBoss Core Services
MySQL Workbench
Splunk Enterprise
SecurID Authentication Manager
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Oracle Communications Cloud Native Core Network Slice Selection Function
Oracle Communications Cloud Native Core Unified Data Repository
Migration Toolkit for Containers
Dell EMC VxRail Appliance
SCALANCE MUM853-1 (EU)
RUGGEDCOM RM1224 LTE(4G) EU
RUGGEDCOM RM1224 LTE(4G) NAM
SCALANCE M804PB
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M826-2 SHDSL-Router
SCALANCE M874-2
SCALANCE M874-3
SCALANCE M876-3 (EVDO)
SCALANCE M876-3 (ROK)
SCALANCE M876-4
SCALANCE M876-4 (EU)
SCALANCE M876-4 (NAM)
SCALANCE MUM856-1 (EU)
SCALANCE MUM856-1 (RoW)
SCALANCE S615 EEC
Splunk Universal Forwarder
Autodesk Civil 3D

How to mitigate CVE-2022-23308

Install updates from vendor's website.

Libxml2 - update to 2.9.13
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-26.el8jbcs, 0.4.10-26.jbcs.el7
cflinuxfs3 - addressed in versions 0.277.0, 0.298.0
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-11.el8jbcs, 1.0.0-11.jbcs.el7
Red Hat OpenShift GitOps - addressed in versions 1.2.3, 1.3.6, 1.4.4
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-91.el8jbcs, 1.6.1-91.jbcs.el7
Harbor - update to 1.10.11
Cloud Pak for Security (CP4S) - update to 1.10.7.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-22.el8jbcs, 1.15.7-22.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.39.2-41.el8jbcs, 1.39.2-41.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-41.el8jbcs, 2.0.8-41.jbcs.el7
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.8, 2.4.3
JBoss Core Services - update to 2.4.37 SP11
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-80.el8jbcs, 2.4.37-80.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-68.GA.el8jbcs, 2.9.2-68.GA.jbcs.el7
Dell Secure Connect Gateway - update to 5.12.00.10
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 12, 7.4.3 Fix Pack 6, 7.5.0 Update Pack 2
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.78.0-3.el8jbcs, 7.78.0-3.jbcs.el7
Tenable Nessus - addressed in versions 8.15.7, 10.3.1
watchOS - update to 8.6 19T572
Splunk Enterprise - addressed in versions 8.1.11, 8.2.7.1, 9.0.1
SecurID Authentication Manager - addressed in versions 8.6 Patch 3, 8.7 Patch 1
macOS - addressed in versions 10.15.7 19H1922, 11.6.6 20G624, 12.4 21F79
Apple iOS - update to 15.5 19F77
iPadOS - update to 15.5 19F77
tvOS - update to 15.5 19L570
Chrome OS - addressed in versions 96.0.4664.208, 96.0.4664.209
Red Hat OpenShift Serverless - update to 1
IBM Integrated Analytics System - update to 1.0.30.0
Migration Toolkit for Containers - addressed in versions 1.5.4, 1.7.1
Netcool Operations Insight - update to 1.6.6
libxml2-debuginfo - update to 2.7.6-0.77.43.1
libxml2 - update to 2.7.6-0.77.43.1
libxml2-debugsource - addressed in versions 2.7.6-0.77.43.1, 2.9.4-46.49.1, 2.9.14-150400.5.7.1
libxml2-python-debuginfo - update to 2.7.6-0.77.43.1
libxml2-python-debugsource - update to 2.7.6-0.77.43.1
libxml2-32bit - update to 2.7.6-0.77.43.1
libxml2-python - update to 2.7.6-0.77.43.1
libxml2-doc - addressed in versions 2.7.6-0.77.43.1, 2.9.4-46.49.1, 2.9.14-150400.5.7.1
libxml2 - addressed in versions 2.9.1-6.6.42, 2.10.3-2
libxml2 (Ubuntu package) - addressed in versions 2.9.4+dfsg1-6.1ubuntu1.5, 2.9.4+dfsg1-6.1ubuntu1.6, 2.9.10+dfsg-5ubuntu0.20.04.2, 2.9.10+dfsg-5ubuntu0.20.04.3, 2.9.12+dfsg-4ubuntu0.1, 2.9.12+dfsg-4ubuntu0.2, 2.9.13+dfsg-1ubuntu0.1
libxml2-utils (Ubuntu package) - addressed in versions 2.9.4+dfsg1-6.1ubuntu1.5, 2.9.4+dfsg1-6.1ubuntu1.6, 2.9.10+dfsg-5ubuntu0.20.04.2, 2.9.10+dfsg-5ubuntu0.20.04.3, 2.9.12+dfsg-4ubuntu0.1, 2.9.12+dfsg-4ubuntu0.2, 2.9.13+dfsg-1ubuntu0.1
libxml2-tools-debuginfo - addressed in versions 2.9.4-46.49.1, 2.9.14-150400.5.7.1
libxml2-2 - addressed in versions 2.9.4-46.49.1, 2.9.14-150400.5.7.1
libxml2-2-32bit - addressed in versions 2.9.4-46.49.1, 2.9.14-150400.5.7.1
libxml2-2-debuginfo - addressed in versions 2.9.4-46.49.1, 2.9.14-150400.5.7.1
libxml2-devel - addressed in versions 2.9.4-46.49.1, 2.9.14-150400.5.7.1
python-libxml2-debugsource - update to 2.9.4-46.49.1
libxml2-2-debuginfo-32bit - update to 2.9.4-46.49.1
libxml2-tools - addressed in versions 2.9.4-46.49.1, 2.9.14-150400.5.7.1
python-libxml2-debuginfo - update to 2.9.4-46.49.1
python-libxml2 - update to 2.9.4-46.49.1
python3-libxml2-python-debuginfo - update to 2.9.7-3.40.1
python3-libxml2-python - update to 2.9.7-3.40.1
python-libxml2-python-debugsource - update to 2.9.7-3.40.1
libxml2 (Red Hat package) - update to 2.9.7-12.el8_5
libxml2 - update to 2.9.7-12.0.1
libxml2-devel - update to 2.9.7-12.0.1
python3-libxml2 - update to 2.9.7-12.0.1
libxml2-help - addressed in versions 2.9.10-25, 2.9.12-13
libxml2-devel - addressed in versions 2.9.10-25, 2.9.12-13
libxml2-debuginfo - addressed in versions 2.9.10-25, 2.9.12-13
python3-libxml2 - addressed in versions 2.9.10-25, 2.9.12-13
libxml2 - addressed in versions 2.9.10-25, 2.9.12-13
libxml2-debugsource - addressed in versions 2.9.10-25, 2.9.12-13
python2-libxml2 - update to 2.9.10-25
libxml2 - addressed in versions 2.9.13-1.fc34, 2.9.13-1.fc35
python3-libxml2-debuginfo - update to 2.9.14-150400.5.7.1
python3-libxml2 - update to 2.9.14-150400.5.7.1
libxml2-devel-32bit - update to 2.9.14-150400.5.7.1
libxml2-2-32bit-debuginfo - update to 2.9.14-150400.5.7.1
dev-libs/libxml2 - update to 2.10.2
Dell EMC VxRail Appliance - addressed in versions 7.0.372, 8.0.000
SCALANCE S615 - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
SCALANCE M804PB - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE M874-2 - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE M876-4 - update to 7.2
SCALANCE M876-4 (EU) - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
SCALANCE S615 EEC - update to 7.2
PowerProtect Data Domain - addressed in versions 7.7.4, 7.10.0.0
Splunk Universal Forwarder - addressed in versions 8.1.11, 8.2.7.1, 9.0.1
Autodesk Civil 3D - addressed in versions 2021.3.6, 2022.2.5, 2023.3, 2024.1

External References

Related Security Bulletins