NULL pointer dereference in Libxml2 - CVE-2022-2309

 

NULL pointer dereference in Libxml2 - CVE-2022-2309

Published: August 29, 2022


Vulnerability identifier: #VU66813
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2309
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error within the iterwalk() function. A remote attacker can pass specially crafted XML data to the application and perform a denial of service (DoS) attack.


Affected software

Libxml2
PowerStore 9000X
PowerStore 1000X
PowerStore 5000X
PowerStore 7000X
PowerStore 3000X
SmartFabric Storage Software
PowerStoreX OS
Gentoo Linux
Oracle Linux
Amazon Linux AMI
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Oracle Solaris
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Public Cloud
openSUSE Leap
Ubuntu
openEuler
Fedora
cflinuxfs3
Platform Automation Toolkit
PowerStore T
OpenManage Network Integration (OMNI)
Dell EMC PowerStore Family Operating System
Enterprise SONiC
IBM Engineering Requirements Management DOORS Next
Isolation Segment
VMware Tanzu Application Service for VMs
Tenable Nessus
Netcool/OMNIbus
VMware Tanzu Operations Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
Splunk Enterprise
libxml2-utils (Ubuntu package)
libxml2 (Ubuntu package)
libxml2
libxml2-debuginfo
libxml2-debugsource
libxml2-devel
python3-libxml2
python2-libxml2
libxml2-help
python-lxml
python2-lxml
python-lxml-debuginfo
python3-lxml
python-lxml-debugsource
python-lxml-help
python-lxml (Red Hat package)
python3-lxml-devel
python3-lxml-doc
python2-lxml-debuginfo
python3-lxml-debuginfo
python2-lxml-devel
dev-python/lxml

How to mitigate CVE-2022-2309

Install update from vendor's website.

Libxml2 - update to 2.10.0
cflinuxfs3 - update to 0.344.0
SmartFabric Storage Software - update to 1.4.3
Isolation Segment - addressed in versions 2.11.25, 2.12.15, 2.13.10
VMware Tanzu Application Service for VMs - addressed in versions 2.11.31, 2.12.20, 2.13.13, 3.0.7
VMware Tanzu Operations Manager - update to 3.0.2
Platform Automation Toolkit - addressed in versions 4.4.30, 5.0.23
Red Hat OpenShift Container Platform - update to 4.13.2
Tenable Nessus - addressed in versions 8.15.7, 10.3.1
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
libxml2-utils (Ubuntu package) - addressed in versions 2.9.4+dfsg1-6.1ubuntu1.8, 2.9.10+dfsg-5ubuntu0.20.04.5, 2.9.13+dfsg-1ubuntu0.2, 2.9.14+dfsg-1.1ubuntu0.1, 2.9.14+dfsg-1ubuntu0.1
libxml2 (Ubuntu package) - addressed in versions 2.9.4+dfsg1-6.1ubuntu1.8, 2.9.10+dfsg-5ubuntu0.20.04.5, 2.9.13+dfsg-1ubuntu0.2, 2.9.14+dfsg-1.1ubuntu0.1, 2.9.14+dfsg-1ubuntu0.1
libxml2 - addressed in versions 2.9.10-38, 2.9.10-40
libxml2-debuginfo - addressed in versions 2.9.10-38, 2.9.10-40
libxml2-debugsource - addressed in versions 2.9.10-38, 2.9.10-40
libxml2-devel - addressed in versions 2.9.10-38, 2.9.10-40
python3-libxml2 - addressed in versions 2.9.10-38, 2.9.10-40
python2-libxml2 - addressed in versions 2.9.10-38, 2.9.10-40
libxml2-help - addressed in versions 2.9.10-38, 2.9.10-40
PowerStoreX OS - update to 3.2.1.5-2424458
PowerStore T - update to 3.6.1.4-2413340
OpenManage Network Integration (OMNI) - update to 3.7
Dell EMC PowerStore Family Operating System - update to 4.0.0.0-2284811
Enterprise SONiC - update to 4.4.1
python-lxml - update to 4.5.2-8
python2-lxml - update to 4.5.2-8
python-lxml-debuginfo - update to 4.5.2-8
python3-lxml - update to 4.5.2-8
python-lxml-debugsource - update to 4.5.2-8
python-lxml-help - update to 4.5.2-8
python-lxml (Red Hat package) - update to 4.6.5-3.el9
python-lxml - update to 4.7.1-3
python-lxml - addressed in versions 4.7.1-3.fc36, 4.9.1-1.fc37, 4.9.1-1.fc38
python3-lxml-devel - addressed in versions 4.7.1-150100.6.6.1, 4.7.1-150200.3.10.1
python3-lxml - addressed in versions 4.7.1-150100.6.6.1, 4.7.1-150200.3.10.1
python3-lxml-doc - addressed in versions 4.7.1-150100.6.6.1, 4.7.1-150200.3.10.1
python2-lxml-debuginfo - update to 4.7.1-150200.3.10.1
python-lxml-debuginfo - update to 4.7.1-150200.3.10.1
python-lxml-debugsource - update to 4.7.1-150200.3.10.1
python3-lxml-debuginfo - update to 4.7.1-150200.3.10.1
python2-lxml - update to 4.7.1-150200.3.10.1
python2-lxml-devel - update to 4.7.1-150200.3.10.1
dev-python/lxml - update to 4.9.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Netcool/OMNIbus - update to 8.1.0.31
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7

External References

Related Security Bulletins