Heap-based buffer overflow in Libxml2 - CVE-2024-34459
Published: May 14, 2024
Vulnerability identifier: #VU89430
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-34459
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when parsing XML data. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and perform a denial of service (DoS) attack.
Affected software
Libxml2
Debian Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Ubuntu
Slackware Linux
Python 3 Module
Basesystem Module
openSUSE Leap
openEuler
Fedora
Voice Gateway
Nokogiri
IBM MQ Operator
Dell Secure Connect Gateway
Nessus Network Monitor
RecoverPoint for Virtual Machines
LANTIME Operating System Firmware (LTOS)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libxml2 (Ubuntu package)
libxml2-2-debuginfo
libxml2-debugsource
libxml2-devel
libxml2-2
python-libxml2-debugsource
libxml2-tools
python-libxml2-debuginfo
python-libxml2
libxml2-tools-debuginfo
libxml2-doc
libxml2-2-debuginfo-32bit
libxml2-2-32bit
libxml2 (Red Hat package)
libxml2
python3-libxml2
python3-libxml2-python-debuginfo
python-libxml2-python-debugsource
python3-libxml2-python
libxml2-help
python2-libxml2
libxml2-debuginfo
libxml2 (Debian package)
libxml2-2-64bit-debuginfo
python311-libxml2
libxml2-python-debugsource
python3-libxml2-debuginfo
libxml2-devel-64bit
libxml2-2-64bit
libxml2-devel-32bit
libxml2-2-32bit-debuginfo
python311-libxml2-debuginfo
libxml2-static
mingw-libxml2
qt6-qtwebengine
IBM supplied MQ Advanced container images
webMethods Managed File Transfer
IBM CICS TX Advanced
Debian Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Ubuntu
Slackware Linux
Python 3 Module
Basesystem Module
openSUSE Leap
openEuler
Fedora
Voice Gateway
Nokogiri
IBM MQ Operator
Dell Secure Connect Gateway
Nessus Network Monitor
RecoverPoint for Virtual Machines
LANTIME Operating System Firmware (LTOS)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libxml2 (Ubuntu package)
libxml2-2-debuginfo
libxml2-debugsource
libxml2-devel
libxml2-2
python-libxml2-debugsource
libxml2-tools
python-libxml2-debuginfo
python-libxml2
libxml2-tools-debuginfo
libxml2-doc
libxml2-2-debuginfo-32bit
libxml2-2-32bit
libxml2 (Red Hat package)
libxml2
python3-libxml2
python3-libxml2-python-debuginfo
python-libxml2-python-debugsource
python3-libxml2-python
libxml2-help
python2-libxml2
libxml2-debuginfo
libxml2 (Debian package)
libxml2-2-64bit-debuginfo
python311-libxml2
libxml2-python-debugsource
python3-libxml2-debuginfo
libxml2-devel-64bit
libxml2-2-64bit
libxml2-devel-32bit
libxml2-2-32bit-debuginfo
python311-libxml2-debuginfo
libxml2-static
mingw-libxml2
qt6-qtwebengine
IBM supplied MQ Advanced container images
webMethods Managed File Transfer
IBM CICS TX Advanced
How to mitigate CVE-2024-34459
Install updates from vendor's website.
Libxml2 - update to 2.12.7
Voice Gateway - update to 1.0.8.12
Nokogiri - update to 1.16.5
IBM MQ Operator - addressed in versions 3.2.26 SC2, 4.0.1 SC2
Nessus Network Monitor - update to 6.5.0
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
LANTIME Operating System Firmware (LTOS) - update to 7.08.020
IBM supplied MQ Advanced container images - update to 10.0.0.0-r2
libxml2 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.9.10+dfsg-5ubuntu0.20.04.8, 2.9.10+dfsg-5ubuntu0.20.04.9, 2.9.13+dfsg-1ubuntu0.5, 2.9.13+dfsg-1ubuntu0.6, 2.9.14+dfsg-1.3ubuntu3.1, 2.9.14+dfsg-1.3ubuntu3.2, 2.12.7+dfsg-3ubuntu0.2
libxml2-2-debuginfo - addressed in versions 2.9.4-46.75.1, 2.9.7-150000.3.70.1, 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-debugsource - addressed in versions 2.9.4-46.75.1, 2.9.7-150000.3.70.1, 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-devel - addressed in versions 2.9.4-46.75.1, 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-2 - addressed in versions 2.9.4-46.75.1, 2.9.7-150000.3.70.1, 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
python-libxml2-debugsource - update to 2.9.4-46.75.1
libxml2-tools - addressed in versions 2.9.4-46.75.1, 2.9.7-150000.3.70.1, 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
python-libxml2-debuginfo - update to 2.9.4-46.75.1
python-libxml2 - update to 2.9.4-46.75.1
libxml2-tools-debuginfo - addressed in versions 2.9.4-46.75.1, 2.9.7-150000.3.70.1, 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-doc - addressed in versions 2.9.4-46.75.1, 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-2-debuginfo-32bit - update to 2.9.4-46.75.1
libxml2-2-32bit - addressed in versions 2.9.4-46.75.1, 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2 (Red Hat package) - addressed in versions 2.9.7-9.el8_4.10, 2.9.7-16.el8_8.14, 2.9.7-21.el8_10.5, 2.9.13-3.el9_2.11, 2.9.13-12.el9_6.2, 2.12.5-9.el10_0.1
libxml2 - addressed in versions 2.9.7-21.0.1, 2.11.5-4
libxml2-devel - addressed in versions 2.9.7-21.0.1, 2.11.5-4
python3-libxml2 - addressed in versions 2.9.7-21.0.1, 2.11.5-4
python3-libxml2-python-debuginfo - update to 2.9.7-150000.3.70.1
python-libxml2-python-debugsource - update to 2.9.7-150000.3.70.1
python3-libxml2-python - update to 2.9.7-150000.3.70.1
libxml2-help - update to 2.9.10-39
python2-libxml2 - update to 2.9.10-39
python3-libxml2 - update to 2.9.10-39
libxml2-devel - update to 2.9.10-39
libxml2-debuginfo - update to 2.9.10-39
libxml2-debugsource - update to 2.9.10-39
libxml2 - update to 2.9.10-39
libxml2 (Debian package) - update to 2.9.14+dfsg-1.3~deb12u2
libxml2-2-64bit-debuginfo - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
python311-libxml2 - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-python-debugsource - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
python3-libxml2-debuginfo - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-devel-64bit - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-2-64bit - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-devel-32bit - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-2-32bit-debuginfo - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
python311-libxml2-debuginfo - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
python3-libxml2 - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-static - update to 2.11.5-4
libxml2-doc - update to 2.11.5-4
libxml2 - update to 2.11.8
mingw-libxml2 - addressed in versions 2.12.7-1.fc39, 2.12.7-1.fc40, 2.12.7-1.fc41
libxml2 - update to 2.12.7-1.fc40
Dell Secure Connect Gateway - update to 5.26.00.18
qt6-qtwebengine - addressed in versions 6.8.2-4.fc40, 6.8.2-4.fc41, 6.8.2-4.fc42
IBM CICS TX Advanced - update to 10.1.0.0 ifix37
Voice Gateway - update to 1.0.8.12
Nokogiri - update to 1.16.5
IBM MQ Operator - addressed in versions 3.2.26 SC2, 4.0.1 SC2
Nessus Network Monitor - update to 6.5.0
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
LANTIME Operating System Firmware (LTOS) - update to 7.08.020
IBM supplied MQ Advanced container images - update to 10.0.0.0-r2
libxml2 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.9.10+dfsg-5ubuntu0.20.04.8, 2.9.10+dfsg-5ubuntu0.20.04.9, 2.9.13+dfsg-1ubuntu0.5, 2.9.13+dfsg-1ubuntu0.6, 2.9.14+dfsg-1.3ubuntu3.1, 2.9.14+dfsg-1.3ubuntu3.2, 2.12.7+dfsg-3ubuntu0.2
libxml2-2-debuginfo - addressed in versions 2.9.4-46.75.1, 2.9.7-150000.3.70.1, 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-debugsource - addressed in versions 2.9.4-46.75.1, 2.9.7-150000.3.70.1, 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-devel - addressed in versions 2.9.4-46.75.1, 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-2 - addressed in versions 2.9.4-46.75.1, 2.9.7-150000.3.70.1, 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
python-libxml2-debugsource - update to 2.9.4-46.75.1
libxml2-tools - addressed in versions 2.9.4-46.75.1, 2.9.7-150000.3.70.1, 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
python-libxml2-debuginfo - update to 2.9.4-46.75.1
python-libxml2 - update to 2.9.4-46.75.1
libxml2-tools-debuginfo - addressed in versions 2.9.4-46.75.1, 2.9.7-150000.3.70.1, 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-doc - addressed in versions 2.9.4-46.75.1, 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-2-debuginfo-32bit - update to 2.9.4-46.75.1
libxml2-2-32bit - addressed in versions 2.9.4-46.75.1, 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2 (Red Hat package) - addressed in versions 2.9.7-9.el8_4.10, 2.9.7-16.el8_8.14, 2.9.7-21.el8_10.5, 2.9.13-3.el9_2.11, 2.9.13-12.el9_6.2, 2.12.5-9.el10_0.1
libxml2 - addressed in versions 2.9.7-21.0.1, 2.11.5-4
libxml2-devel - addressed in versions 2.9.7-21.0.1, 2.11.5-4
python3-libxml2 - addressed in versions 2.9.7-21.0.1, 2.11.5-4
python3-libxml2-python-debuginfo - update to 2.9.7-150000.3.70.1
python-libxml2-python-debugsource - update to 2.9.7-150000.3.70.1
python3-libxml2-python - update to 2.9.7-150000.3.70.1
libxml2-help - update to 2.9.10-39
python2-libxml2 - update to 2.9.10-39
python3-libxml2 - update to 2.9.10-39
libxml2-devel - update to 2.9.10-39
libxml2-debuginfo - update to 2.9.10-39
libxml2-debugsource - update to 2.9.10-39
libxml2 - update to 2.9.10-39
libxml2 (Debian package) - update to 2.9.14+dfsg-1.3~deb12u2
libxml2-2-64bit-debuginfo - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
python311-libxml2 - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-python-debugsource - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
python3-libxml2-debuginfo - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-devel-64bit - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-2-64bit - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-devel-32bit - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-2-32bit-debuginfo - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
python311-libxml2-debuginfo - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
python3-libxml2 - addressed in versions 2.9.14-150400.5.32.1, 2.10.3-150500.5.17.1
libxml2-static - update to 2.11.5-4
libxml2-doc - update to 2.11.5-4
libxml2 - update to 2.11.8
mingw-libxml2 - addressed in versions 2.12.7-1.fc39, 2.12.7-1.fc40, 2.12.7-1.fc41
libxml2 - update to 2.12.7-1.fc40
Dell Secure Connect Gateway - update to 5.26.00.18
qt6-qtwebengine - addressed in versions 6.8.2-4.fc40, 6.8.2-4.fc41, 6.8.2-4.fc42
IBM CICS TX Advanced - update to 10.1.0.0 ifix37
External References
Related Security Bulletins
- Denial of service in Libxml2
- Nokogiri update for libxml2
- Fedora 40 update for libxml2
- Fedora 40 update for mingw-libxml2
- Fedora 41 update for mingw-libxml2
- Fedora 39 update for mingw-libxml2
- openEuler update for libxml2
- Slackware Linux update for libxml2
- SUSE update for libxml2
- SUSE update for libxml2
- SUSE update for libxml2
- SUSE update for libxml2
- Multiple vulnerabilities in Nessus Network Monitor
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Ubuntu update for libxml2
- Ubuntu update for libxml2
- Fedora 40 update for qt6-qtwebengine
- Fedora 41 update for qt6-qtwebengine
- Fedora 42 update for qt6-qtwebengine
- Anolis OS update for libxml2
- Multiple vulnerabilities in IBM webMethods Managed File Transfer
- Multiple vulnerabilities in IBM CICS TX Advanced
- Meinberg LANTIME firmware update for third-party components (February 2025)
- Dell RecoverPoint for Virtual Machines update for third-party components
- Multiple vulnerabilities in IBM Voice Gateway
- Debian update for libxml2
- Red Hat Enterprise Linux 8 update for libxml2
- Red Hat Enterprise Linux 8 update for libxml2
- Red Hat Enterprise Linux 8 update for libxml2
- Anolis OS update for libxml2
- Red Hat Enterprise Linux 9 update for libxml2
- Red Hat Enterprise Linux 9 update for libxml2
- Red Hat Enterprise Linux 10 update for libxml2
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images