Use-after-free in Libxml2 - CVE-2022-23308

 

Use-after-free in Libxml2 - CVE-2022-23308

Published: March 1, 2022


Vulnerability identifier: #VU60922
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2022-23308
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Libxml2
Gentoo Linux
Amazon Linux AMI
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
Anolis OS
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
watchOS
macOS
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Slackware Linux
Ubuntu
Apple iOS
iPadOS
tvOS
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
openEuler
Fedora
Chrome OS
SINAMICS GL150
SINAMICS PERFECT HARMONY GH180 6SR5
SINAMICS SL150
SCALANCE S615
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
libxml2-debuginfo
libxml2
libxml2-debugsource
libxml2-python-debuginfo
libxml2-python-debugsource
libxml2-32bit
libxml2-python
libxml2-doc
libxml2 (Ubuntu package)
libxml2-utils (Ubuntu package)
libxml2-tools-debuginfo
libxml2-2
libxml2-2-32bit
libxml2-2-debuginfo
libxml2-devel
python-libxml2-debugsource
libxml2-2-debuginfo-32bit
libxml2-tools
python-libxml2-debuginfo
python-libxml2
python3-libxml2-python-debuginfo
python3-libxml2-python
python-libxml2-python-debugsource
libxml2 (Red Hat package)
python3-libxml2
libxml2-help
python2-libxml2
python3-libxml2-debuginfo
libxml2-devel-32bit
libxml2-2-32bit-debuginfo
dev-libs/libxml2
cflinuxfs3
IBM Watson Machine Learning Accelerator
Red Hat OpenShift GitOps
IBM Integrated Analytics System
Harbor
Red Hat OpenShift Serverless
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Object Storage Systems
Dell Secure Connect Gateway
Tenable Nessus
Oracle Communications Cloud Native Core Network Repository Function
Oracle Communications Cloud Native Core Binding Support Function
Netcool Operations Insight
PowerProtect Data Domain
JBoss Core Services
MySQL Workbench
Splunk Enterprise
SecurID Authentication Manager
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Oracle Communications Cloud Native Core Network Slice Selection Function
Oracle Communications Cloud Native Core Unified Data Repository
Migration Toolkit for Containers
Dell EMC VxRail Appliance
SCALANCE MUM853-1 (EU)
RUGGEDCOM RM1224 LTE(4G) EU
RUGGEDCOM RM1224 LTE(4G) NAM
SCALANCE M804PB
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M826-2 SHDSL-Router
SCALANCE M874-2
SCALANCE M874-3
SCALANCE M876-3 (EVDO)
SCALANCE M876-3 (ROK)
SCALANCE M876-4
SCALANCE M876-4 (EU)
SCALANCE M876-4 (NAM)
SCALANCE MUM856-1 (EU)
SCALANCE MUM856-1 (RoW)
SCALANCE S615 EEC
Splunk Universal Forwarder
Autodesk Civil 3D

Detailed vulnerability description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when processing ID and IDREF attributes in valid.c. A remote attacker can pass specially crafted XML input to the application, trigger a use-after-free error and crash the application or execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


How to mitigate CVE-2022-23308

Install updates from vendor's website.

Sources