NULL pointer dereference in Libxml2 - CVE-2022-2309
Published: August 29, 2022
Vulnerability identifier: #VU66813
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2309
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the iterwalk() function. A remote attacker can pass specially crafted XML data to the application and perform a denial of service (DoS) attack.
Affected software
Libxml2
PowerStore 9000X
PowerStore 1000X
PowerStore 5000X
PowerStore 7000X
PowerStore 3000X
SmartFabric Storage Software
PowerStoreX OS
Gentoo Linux
Oracle Linux
Amazon Linux AMI
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Oracle Solaris
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Public Cloud
openSUSE Leap
Ubuntu
openEuler
Fedora
cflinuxfs3
Platform Automation Toolkit
PowerStore T
OpenManage Network Integration (OMNI)
Dell EMC PowerStore Family Operating System
Enterprise SONiC
IBM Engineering Requirements Management DOORS Next
Isolation Segment
VMware Tanzu Application Service for VMs
Tenable Nessus
Netcool/OMNIbus
VMware Tanzu Operations Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
Splunk Enterprise
libxml2-utils (Ubuntu package)
libxml2 (Ubuntu package)
libxml2
libxml2-debuginfo
libxml2-debugsource
libxml2-devel
python3-libxml2
python2-libxml2
libxml2-help
python-lxml
python2-lxml
python-lxml-debuginfo
python3-lxml
python-lxml-debugsource
python-lxml-help
python-lxml (Red Hat package)
python3-lxml-devel
python3-lxml-doc
python2-lxml-debuginfo
python3-lxml-debuginfo
python2-lxml-devel
dev-python/lxml
PowerStore 9000X
PowerStore 1000X
PowerStore 5000X
PowerStore 7000X
PowerStore 3000X
SmartFabric Storage Software
PowerStoreX OS
Gentoo Linux
Oracle Linux
Amazon Linux AMI
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Oracle Solaris
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Public Cloud
openSUSE Leap
Ubuntu
openEuler
Fedora
cflinuxfs3
Platform Automation Toolkit
PowerStore T
OpenManage Network Integration (OMNI)
Dell EMC PowerStore Family Operating System
Enterprise SONiC
IBM Engineering Requirements Management DOORS Next
Isolation Segment
VMware Tanzu Application Service for VMs
Tenable Nessus
Netcool/OMNIbus
VMware Tanzu Operations Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
Splunk Enterprise
libxml2-utils (Ubuntu package)
libxml2 (Ubuntu package)
libxml2
libxml2-debuginfo
libxml2-debugsource
libxml2-devel
python3-libxml2
python2-libxml2
libxml2-help
python-lxml
python2-lxml
python-lxml-debuginfo
python3-lxml
python-lxml-debugsource
python-lxml-help
python-lxml (Red Hat package)
python3-lxml-devel
python3-lxml-doc
python2-lxml-debuginfo
python3-lxml-debuginfo
python2-lxml-devel
dev-python/lxml
How to mitigate CVE-2022-2309
Install update from vendor's website.
Libxml2 - update to 2.10.0
cflinuxfs3 - update to 0.344.0
SmartFabric Storage Software - update to 1.4.3
Isolation Segment - addressed in versions 2.11.25, 2.12.15, 2.13.10
VMware Tanzu Application Service for VMs - addressed in versions 2.11.31, 2.12.20, 2.13.13, 3.0.7
VMware Tanzu Operations Manager - update to 3.0.2
Platform Automation Toolkit - addressed in versions 4.4.30, 5.0.23
Red Hat OpenShift Container Platform - update to 4.13.2
Tenable Nessus - addressed in versions 8.15.7, 10.3.1
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
libxml2-utils (Ubuntu package) - addressed in versions 2.9.4+dfsg1-6.1ubuntu1.8, 2.9.10+dfsg-5ubuntu0.20.04.5, 2.9.13+dfsg-1ubuntu0.2, 2.9.14+dfsg-1.1ubuntu0.1, 2.9.14+dfsg-1ubuntu0.1
libxml2 (Ubuntu package) - addressed in versions 2.9.4+dfsg1-6.1ubuntu1.8, 2.9.10+dfsg-5ubuntu0.20.04.5, 2.9.13+dfsg-1ubuntu0.2, 2.9.14+dfsg-1.1ubuntu0.1, 2.9.14+dfsg-1ubuntu0.1
libxml2 - addressed in versions 2.9.10-38, 2.9.10-40
libxml2-debuginfo - addressed in versions 2.9.10-38, 2.9.10-40
libxml2-debugsource - addressed in versions 2.9.10-38, 2.9.10-40
libxml2-devel - addressed in versions 2.9.10-38, 2.9.10-40
python3-libxml2 - addressed in versions 2.9.10-38, 2.9.10-40
python2-libxml2 - addressed in versions 2.9.10-38, 2.9.10-40
libxml2-help - addressed in versions 2.9.10-38, 2.9.10-40
PowerStoreX OS - update to 3.2.1.5-2424458
PowerStore T - update to 3.6.1.4-2413340
OpenManage Network Integration (OMNI) - update to 3.7
Dell EMC PowerStore Family Operating System - update to 4.0.0.0-2284811
Enterprise SONiC - update to 4.4.1
python-lxml - update to 4.5.2-8
python2-lxml - update to 4.5.2-8
python-lxml-debuginfo - update to 4.5.2-8
python3-lxml - update to 4.5.2-8
python-lxml-debugsource - update to 4.5.2-8
python-lxml-help - update to 4.5.2-8
python-lxml (Red Hat package) - update to 4.6.5-3.el9
python-lxml - update to 4.7.1-3
python-lxml - addressed in versions 4.7.1-3.fc36, 4.9.1-1.fc37, 4.9.1-1.fc38
python3-lxml-devel - addressed in versions 4.7.1-150100.6.6.1, 4.7.1-150200.3.10.1
python3-lxml - addressed in versions 4.7.1-150100.6.6.1, 4.7.1-150200.3.10.1
python3-lxml-doc - addressed in versions 4.7.1-150100.6.6.1, 4.7.1-150200.3.10.1
python2-lxml-debuginfo - update to 4.7.1-150200.3.10.1
python-lxml-debuginfo - update to 4.7.1-150200.3.10.1
python-lxml-debugsource - update to 4.7.1-150200.3.10.1
python3-lxml-debuginfo - update to 4.7.1-150200.3.10.1
python2-lxml - update to 4.7.1-150200.3.10.1
python2-lxml-devel - update to 4.7.1-150200.3.10.1
dev-python/lxml - update to 4.9.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Netcool/OMNIbus - update to 8.1.0.31
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
cflinuxfs3 - update to 0.344.0
SmartFabric Storage Software - update to 1.4.3
Isolation Segment - addressed in versions 2.11.25, 2.12.15, 2.13.10
VMware Tanzu Application Service for VMs - addressed in versions 2.11.31, 2.12.20, 2.13.13, 3.0.7
VMware Tanzu Operations Manager - update to 3.0.2
Platform Automation Toolkit - addressed in versions 4.4.30, 5.0.23
Red Hat OpenShift Container Platform - update to 4.13.2
Tenable Nessus - addressed in versions 8.15.7, 10.3.1
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
libxml2-utils (Ubuntu package) - addressed in versions 2.9.4+dfsg1-6.1ubuntu1.8, 2.9.10+dfsg-5ubuntu0.20.04.5, 2.9.13+dfsg-1ubuntu0.2, 2.9.14+dfsg-1.1ubuntu0.1, 2.9.14+dfsg-1ubuntu0.1
libxml2 (Ubuntu package) - addressed in versions 2.9.4+dfsg1-6.1ubuntu1.8, 2.9.10+dfsg-5ubuntu0.20.04.5, 2.9.13+dfsg-1ubuntu0.2, 2.9.14+dfsg-1.1ubuntu0.1, 2.9.14+dfsg-1ubuntu0.1
libxml2 - addressed in versions 2.9.10-38, 2.9.10-40
libxml2-debuginfo - addressed in versions 2.9.10-38, 2.9.10-40
libxml2-debugsource - addressed in versions 2.9.10-38, 2.9.10-40
libxml2-devel - addressed in versions 2.9.10-38, 2.9.10-40
python3-libxml2 - addressed in versions 2.9.10-38, 2.9.10-40
python2-libxml2 - addressed in versions 2.9.10-38, 2.9.10-40
libxml2-help - addressed in versions 2.9.10-38, 2.9.10-40
PowerStoreX OS - update to 3.2.1.5-2424458
PowerStore T - update to 3.6.1.4-2413340
OpenManage Network Integration (OMNI) - update to 3.7
Dell EMC PowerStore Family Operating System - update to 4.0.0.0-2284811
Enterprise SONiC - update to 4.4.1
python-lxml - update to 4.5.2-8
python2-lxml - update to 4.5.2-8
python-lxml-debuginfo - update to 4.5.2-8
python3-lxml - update to 4.5.2-8
python-lxml-debugsource - update to 4.5.2-8
python-lxml-help - update to 4.5.2-8
python-lxml (Red Hat package) - update to 4.6.5-3.el9
python-lxml - update to 4.7.1-3
python-lxml - addressed in versions 4.7.1-3.fc36, 4.9.1-1.fc37, 4.9.1-1.fc38
python3-lxml-devel - addressed in versions 4.7.1-150100.6.6.1, 4.7.1-150200.3.10.1
python3-lxml - addressed in versions 4.7.1-150100.6.6.1, 4.7.1-150200.3.10.1
python3-lxml-doc - addressed in versions 4.7.1-150100.6.6.1, 4.7.1-150200.3.10.1
python2-lxml-debuginfo - update to 4.7.1-150200.3.10.1
python-lxml-debuginfo - update to 4.7.1-150200.3.10.1
python-lxml-debugsource - update to 4.7.1-150200.3.10.1
python3-lxml-debuginfo - update to 4.7.1-150200.3.10.1
python2-lxml - update to 4.7.1-150200.3.10.1
python2-lxml-devel - update to 4.7.1-150200.3.10.1
dev-python/lxml - update to 4.9.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Netcool/OMNIbus - update to 8.1.0.31
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
External References
Related Security Bulletins
- NULL pointer dereference in Libxml2
- SUSE update for python-lxml
- SUSE update for python-lxml
- Gentoo update for lxml
- Multiple vulnerabilities in Tenable Nessus
- Multiple vulnerabilities in Tenable Nessus
- Red Hat Enterprise Linux 9 update for python-lxml
- Ubuntu update for libxml2
- Multiple vulnerabilities in cflinuxfs3
- Multiple vulnerabilities in VMware Products
- Multiple vulnerabilities in Oracle Solaris
- Ubuntu update for libxml2
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in Oracle Linux
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform release 4.13
- NULL pointer dereference in Tivoli Netcool/OMNIbus
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- openEuler update for python-lxml
- openEuler 20.03 LTS SP1 update for libxml2
- openEuler 20.03 LTS SP4 update for libxml2
- Multiple vulnerabilities in Dell PowerStore Family
- Amazon Linux AMI update for python-lxml
- Fedora 38 update for python-lxml
- Fedora 37 update for python-lxml
- Fedora 36 update for python-lxml
- Multiple vulnerabilities in Enterprise SONiC Distribution
- Multiple vulnerabilities in Dell PowerStore T
- Multiple vulnerabilities in Dell OpenManage Network Integration (OMNI)
- Dell SmartFabric Storage Software update for third-party components
- Multiple vulnerabilities in Dell PowerStore X