Resource management error in Libxml2 - CVE-2022-40304
Published: October 30, 2022 / Updated: February 8, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists in entities.c due to the way libxml2 handles reference cycles. The library does not anticipate that entity content can be allocated from a dict and clears it upon reference cycle detection by setting its first byte to zero. This can lead to memory corruption issues, such as double free errors and result in a denial of service.
Affected software
HPE B-series SN6750B Fibre Channel Switch
Brocade 32Gb Fibre Channel SAN Switch for HPE Synergy
HPE SN8700B 4-slot SAN Director Switch
HPE SN8700B 8-slot SAN Director Switch
HPE SN8600B 4-slot SAN Director Switch
HPE B-series SN2600B SAN Extension Switch
HPE SN8600B 8-slot SAN Director Switch
HPE B-series SN6650B Fibre Channel Switch
HPE B-series SN6700B Fibre Channel Switch
HPE B-series SN6600B Fibre Channel Switch
HPE B-series SN4700B SAN Extension Switch
HPE B-series SN3600B Fibre Channel Switch
Dell EMC VxRail Appliance
Debian Linux
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
Oracle Linux
SUSE Linux Enterprise Storage
IBM AIX
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
watchOS
macOS
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Slackware Linux
Ubuntu
iPadOS
Apple iOS
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Python2
openSUSE Leap
tvOS
openEuler
Fedora
Brocade Fabric OS
VMware Tanzu Application Service for VMs
Isolation Segment
Submariner
NetObserv Operator
Data Lakehouse
Migration Toolkit for Runtimes
Service Telemetry Framework
Migration Toolkit for Virtualization
Red Hat Advanced Cluster Management for Kubernetes
IBM Watson Assistant for IBM Cloud Pak for Data
OpenShift Logging
Red Hat Migration Toolkit for Applications
Oracle HTTP Server
Red Hat OpenStack
Oracle Communications Cloud Native Core Binding Support Function
Netcool Operations Insight
IBM MQ Operator
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
cflinuxfs3
Xenial Stemcells
Platform Automation Toolkit
IBM MQ Appliance
ObjectScale
Tanzu Greenplum for Kubernetes
Cloud Pak for Network Automation
PowerStore T
IBM Cloud Pak for Watson AIOps
IBM supplied MQ Advanced container images
Robotic Process Automation for Cloud Pak
Self Node Remediation Operator
Red Hat OpenShift Serverless
OpenShift sandboxed containers
OpenShift Service Mesh
VMware Tanzu Operations Manager
Red Hat OpenShift Data Science
OpenShift Data Foundation (formerly OpenShift Container Storage)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Dell EMC Container Storage Modules
Red Hat OpenShift GitOps
IBM VIOS
IBM Qradar SIEM
Cloud Pak for Security (CP4S)
TeleControl Server Basic
Red Hat Single Sign-On
MySQL Workbench
OpenShift Developer Tools and Services
Splunk Universal Forwarder
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libxml2-utils (Ubuntu package)
libxml2 (Ubuntu package)
xmlsec1
libxml2
libxml2-doc
libxml2-tools
libxml2-2-debuginfo-32bit
libxml2-tools-debuginfo
libxml2-2
libxml2-2-32bit
libxml2-devel
libxml2-debugsource
libxml2-2-debuginfo
python-libxml2-debuginfo
python-libxml2
python-libxml2-debugsource
libxml2 (Red Hat package)
python3-libxml2
python3-libxml2-python-debuginfo
python2-libxml2-python-debuginfo
python3-libxml2-python
python-libxml2-python-debugsource
python2-libxml2-python
libxml2-2-32bit-debuginfo
libxml2-devel-32bit
libxml2 (Debian package)
python2-libxml2
libxml2-debuginfo
libxml2-help
python3-libxml2-debuginfo
libxml2-python-debugsource
dev-libs/libxml2
Oracle Communications Cloud Native Core Network Slice Selection Function
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
RSA Authentication Manager
IBM DS8000 Hardware Management Console
Autodesk Civil 3D
How to mitigate CVE-2022-40304
VMware Tanzu Application Service for VMs - addressed in versions 2.11.31, 2.12.20, 2.13.13, 3.0.7
Isolation Segment - addressed in versions 2.11.25, 2.12.15, 2.13.10
cflinuxfs3 - update to 0.344.0
Submariner - update to 0.14.0
NetObserv Operator - update to 1.1.0
Self Node Remediation Operator - update to 0.5.1
Data Lakehouse - update to 1.1.0.0
Red Hat OpenShift Serverless - addressed in versions 1.27.0, 1.27.1
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.1.1
Migration Toolkit for Runtimes - update to 1.0.2
OpenShift API for Data Protection (OADP) - update to 1.1.2
OpenShift sandboxed containers - update to 1.4.1
Migration Toolkit for Containers - update to 1.7.7
Red Hat OpenShift GitOps - addressed in versions 1.5.9, 1.6.4, 1.7, 1.10.0, 1.11
Service Telemetry Framework - update to 1.5.4
OpenShift Service Mesh - update to 2.3.2
Migration Toolkit for Virtualization - update to 2.4.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.4, 2.7.0
Xenial Stemcells - update to 621.364
VMware Tanzu Operations Manager - addressed in versions 2.10.51, 3.0.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
Platform Automation Toolkit - addressed in versions 4.4.30, 5.0.23
Red Hat OpenShift Container Platform - update to 4.13.2
OpenShift Logging - addressed in versions 5.4.11, 5.6.1
Red Hat Migration Toolkit for Applications - update to 6.0.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 8
Red Hat Single Sign-On - update to 7.6.2
MySQL Workbench - update to 8.0.32
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
watchOS - update to 9.2 20S361
IBM MQ Appliance - addressed in versions 9.3.0.5, 9.3.2.1
macOS - addressed in versions 11.7.2 20G1020, 12.6.2 21G320, 13.0.1 22A400
iPadOS - addressed in versions 15.7.2 19H218, 16.1.1 20B101
Apple iOS - addressed in versions 15.7.2 19H218, 16.1.1 20B101
tvOS - update to 16.2 20K362
libxml2-utils (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.9.4+dfsg1-6.1ubuntu1.8, 2.9.10+dfsg-5ubuntu0.20.04.5, 2.9.13+dfsg-1ubuntu0.2, 2.9.14+dfsg-1ubuntu0.1
libxml2 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.9.4+dfsg1-6.1ubuntu1.8, 2.9.10+dfsg-5ubuntu0.20.04.5, 2.9.13+dfsg-1ubuntu0.2, 2.9.14+dfsg-1ubuntu0.1
xmlsec1 - addressed in versions 1.2.29-5.fc35, 1.2.33-3.fc36, 1.2.34-4.fc37
xmlsec1 - update to 1.2.33-3
ObjectScale - update to 1.4.0
Dell EMC Container Storage Modules - update to 1.6.0
Netcool Operations Insight - update to 1.6.12
Cloud Pak for Security (CP4S) - update to 1.10.12.0
Red Hat OpenShift Data Science - update to 1.22.1
Tanzu Greenplum for Kubernetes - update to 2.0.0
IBM MQ Operator - addressed in versions 2.0.7, 2.2.2
Cloud Pak for Network Automation - update to 2.4.5
libxml2 - addressed in versions 2.9.1-6.6.42, 2.10.3-2
libxml2-doc - addressed in versions 2.9.4-46.59.2, 2.9.7-150000.3.51.1, 2.9.14-150400.5.10.1
libxml2-tools - addressed in versions 2.9.4-46.59.2, 2.9.7-150000.3.51.1, 2.9.14-150400.5.10.1
libxml2-2-debuginfo-32bit - update to 2.9.4-46.59.2
libxml2-tools-debuginfo - addressed in versions 2.9.4-46.59.2, 2.9.7-150000.3.51.1, 2.9.14-150400.5.10.1
libxml2-2 - addressed in versions 2.9.4-46.59.2, 2.9.7-150000.3.51.1, 2.9.14-150400.5.10.1
libxml2-2-32bit - addressed in versions 2.9.4-46.59.2, 2.9.7-150000.3.51.1, 2.9.14-150400.5.10.1
libxml2-devel - addressed in versions 2.9.4-46.59.2, 2.9.7-150000.3.51.1, 2.9.14-150400.5.10.1
libxml2-debugsource - addressed in versions 2.9.4-46.59.2, 2.9.7-150000.3.51.1, 2.9.14-150400.5.10.1
libxml2-2-debuginfo - addressed in versions 2.9.4-46.59.2, 2.9.7-150000.3.51.1, 2.9.14-150400.5.10.1
python-libxml2-debuginfo - update to 2.9.4-46.59.3
python-libxml2 - update to 2.9.4-46.59.3
python-libxml2-debugsource - update to 2.9.4-46.59.3
libxml2 (Red Hat package) - addressed in versions 2.9.7-13.el8_6.4, 2.9.7-15.el8_7.1, 2.9.13-3.el9_1
libxml2-devel - update to 2.9.7-15.0.1
python3-libxml2 - update to 2.9.7-15.0.1
libxml2 - update to 2.9.7-15.0.1
python3-libxml2-python-debuginfo - update to 2.9.7-150000.3.51.1
python2-libxml2-python-debuginfo - update to 2.9.7-150000.3.51.1
python3-libxml2-python - update to 2.9.7-150000.3.51.1
python-libxml2-python-debugsource - update to 2.9.7-150000.3.51.1
python2-libxml2-python - update to 2.9.7-150000.3.51.1
libxml2-2-32bit-debuginfo - addressed in versions 2.9.7-150000.3.51.1, 2.9.14-150400.5.10.1
libxml2-devel-32bit - addressed in versions 2.9.7-150000.3.51.1, 2.9.14-150400.5.10.1
libxml2 (Debian package) - update to 2.9.10+dfsg-6.7+deb11u3
libxml2 - addressed in versions 2.9.10-32, 2.9.10-34, 2.9.12-13
python3-libxml2 - addressed in versions 2.9.10-32, 2.9.10-34, 2.9.12-13
libxml2-devel - addressed in versions 2.9.10-32, 2.9.10-34, 2.9.12-13
python2-libxml2 - addressed in versions 2.9.10-32, 2.9.10-34
libxml2-debugsource - addressed in versions 2.9.10-32, 2.9.10-34, 2.9.12-13
libxml2-debuginfo - addressed in versions 2.9.10-32, 2.9.10-34, 2.9.12-13
libxml2-help - addressed in versions 2.9.10-32, 2.9.10-34, 2.9.12-13
python3-libxml2-debuginfo - update to 2.9.14-150400.5.10.1
python3-libxml2 - update to 2.9.14-150400.5.10.1
libxml2-python-debugsource - update to 2.9.14-150400.5.10.1
dev-libs/libxml2 - update to 2.10.3
libxml2 - addressed in versions 2.10.3-1.fc36, 2.10.3-2.fc35, 2.10.3-2.fc37
libxml2 - update to 2.12.2
TeleControl Server Basic - update to 3.1.2
PowerStore T - update to 3.5.0.1-2083289
IBM Cloud Pak for Watson AIOps - update to 4.1.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.1
EMC ViPR SRM - update to 4.8.0.1
OpenShift Developer Tools and Services - update to 4.9
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Dell EMC VxRail Appliance - update to 7.0.411
RSA Authentication Manager - update to 8.7 Patch 2
Brocade Fabric OS - addressed in versions 9.1.1d2, 9.2.0b1, 9.2.1
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.3-r1, 9.3.1.1-r1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.3, 23.0.3
IBM DS8000 Hardware Management Console - update to 89.33.34.0
Autodesk Civil 3D - addressed in versions 2021.3.6, 2022.2.5, 2023.3, 2024.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Libxml2
- SUSE update for libxml2
- SUSE update for libxml2
- Gentoo update for libxml2
- SUSE update for libxml2
- Debian update for libxml2
- Apple macOS Ventura update for libxml2
- Apple iOS and iPadOS update for libxml2
- Ubuntu update for libxml2
- Ubuntu update for libxml2
- Multiple vulnerabilities in cflinuxfs3
- Multiple vulnerabilities in macOS Monterey
- Multiple vulnerabilities in Apple macOS Big Sur
- Multiple vulnerabilities in Apple iOS 15 and iPadOS 15
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Dell SRM and Dell Storage Monitoring and Reporting
- Red Hat Enterprise Linux 8 update for libxml2
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Slice Selection Function
- Multiple vulnerabilities in MySQL Workbench
- Multiple vulnerabilities in Oracle Linux
- Red Hat Enterprise Linux 9 update for libxml2
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.5
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.7
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.6
- Multiple vulnerabilities in Submariner
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes
- IBM AIX update for libxml2
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Multiple vulnerabilities in OpenShift Serverless
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Multiple vulnerabilities in Red Hat OpenShift Logging 5.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.6
- Red Hat Advanced Cluster Management for Kubernetes 2.6 update for Submariner
- Multiple vulnerabilities in NetObserv Operator
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in OpenShift Developer Tools and Services
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6 for OpenShift
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Multiple vulnerabilities in VMware Products
- Multiple vulnerabilities in VMware Products
- Multiple vulnerabilities in Red Hat OpenStack Platform 16.2
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.1
- Multiple vulnerabilities in OpenShift Serverless
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Migration Toolkit for Runtimes
- Multiple vulnerabilities in Oracle Solaris
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.3
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Resource management error in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in Oracle HTTP Server
- Resource management error in Oracle Communications Cloud Native Core Network Function Cloud Native Environment
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Multiple vulnerabilities in IBM MQ Appliance
- Amazon Linux AMI update for libxml2
- Multiple vulnerabilities in Red Hat OpenShift Data Science 1.22
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift
- Splunk Universal Forwarder update for third-party packages
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in IBM DS8000 Hardware Management Console (HMC)
- Multiple vulnerabilities in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in Dell Container Storage Modules
- Multiple vulnerabilities in OpenShift sandboxed containers 1.4
- Multiple vulnerabilities in Dell PowerStore Family
- Autodesk Civil 3D update for libxml2
- Multiple vulnerabilities in Red Hat OpenShift Container Platform release 4.13
- Multiple vulnerabilities in Red Hat Self Node Remediation Operator 0.5
- Multiple vulnerabilities in Migration Toolkit for Virtualization 2.4
- Slackware Linux update for libxml2
- Red Hat Enterprise Linux 8.6 Extended Update Support update for libxml2
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- openEuler 20.03 LTS SP1 update for libxml2
- openEuler 20.03 LTS SP3 update for libxml2
- openEuler 22.03 LTS update for libxml2
- Multiple vulnerabilities in Service Telemetry Framework 1.5
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Siemens Telecontrol Server Basic
- Multiple vulnerabilities in Dell Data Lakehouse System Software
- Amazon Linux AMI update for libxml2
- Amazon Linux AMI update for xmlsec1
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in HPE Brocade Fabric OS
- Fedora 37 update for libxml2, xmlsec1
- Fedora 36 update for libxml2, xmlsec1
- Fedora 35 update for libxml2, xmlsec1
- Anolis OS update for libxml2
- RSA Authentication Manager update for third-party components