CVE-2022-23308
Summary
| CVE | CVE-2022-23308 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-26 05:15:00 UTC |
| Updated | 2023-11-07 03:44:00 UTC |
| Description | valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| libxml2: Multiple Vulnerabilities (GLSA 202210-03) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| About the security content of iOS 15.5 and iPadOS 15.5 - Apple Support |
CONFIRM |
support.apple.com |
|
| About the security content of macOS Big Sur 11.6.6 - Apple Support |
CONFIRM |
support.apple.com |
|
| Full Disclosure: APPLE-SA-2022-05-16-2 macOS Monterey 12.4 |
FULLDISC |
seclists.org |
|
| About the security content of macOS Monterey 12.4 - Apple Support |
CONFIRM |
support.apple.com |
|
| CVE-2022-23308 Libxml2 Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [SECURITY] [DLA 2972-1] libxml2 security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 34 Update: libxml2-2.9.13-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| NEWS · v2.9.13 · GNOME / libxml2 · GitLab |
MISC |
gitlab.gnome.org |
|
| Full Disclosure: APPLE-SA-2022-05-16-5 watchOS 8.6 |
FULLDISC |
seclists.org |
|
| About the security content of Security Update 2022-004 Catalina - Apple Support |
CONFIRM |
support.apple.com |
|
| About the security content of watchOS 8.6 - Apple Support |
CONFIRM |
support.apple.com |
|
| Full Disclosure: APPLE-SA-2022-05-16-6 tvOS 15.5 |
FULLDISC |
seclists.org |
|
| About the security content of tvOS 15.5 - Apple Support |
CONFIRM |
support.apple.com |
|
| Full Disclosure: APPLE-SA-2022-05-16-1 iOS 15.5 and iPadOS 15.5 |
FULLDISC |
seclists.org |
|
| [SECURITY] Fedora 34 Update: libxml2-2.9.13-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Full Disclosure: APPLE-SA-2022-05-16-3 macOS Big Sur 11.6.6 |
FULLDISC |
seclists.org |
|
| [CVE-2022-23308] Use-after-free of ID and IDREF attributes · GNOME/libxml2@652dd12 · GitHub |
CONFIRM |
github.com |
|
| Full Disclosure: APPLE-SA-2022-05-16-4 Security Update 2022-004 Catalina |
FULLDISC |
seclists.org |
|
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159707 Oracle Enterprise Linux Security Update for libxml2 (ELSA-2022-0899)
- 179176 Debian Security Update for libxml2 (DLA 2972-1)
- 179208 Debian Security Update for libxml2 (CVE-2022-23308)
- 198697 Ubuntu Security Notification for libxml2 Vulnerability (USN-5324-1)
- 198787 Ubuntu Security Notification for libxml2 Vulnerabilities (USN-5422-1)
- 240152 Red Hat Update for libxml2 (RHSA-2022:0899)
- 240235 Red Hat Update for JBoss Core Services (RHSA-2022:1389)
- 282425 Fedora Security Update for libxml2 (FEDORA-2022-b661dea83d)
- 282462 Fedora Security Update for libxml2 (FEDORA-2022-050c712ed7)
- 296063 Oracle Solaris 11.4 Support Repository Update (SRU) 45.119.2 Missing (CPUAPR2022)
- 354006 Amazon Linux Security Advisory for libxml2 : ALAS2-2022-1826
- 354464 Amazon Linux Security Advisory for libxml2 : ALAS2022-2022-198
- 354486 Amazon Linux Security Advisory for libxml2 : ALAS2022-2022-068
- 354638 Amazon Linux Security Advisory for libxml2 : AL2012-2022-370
- 354929 Amazon Linux Security Advisory for libxml2 : ALAS-2023-1743
- 355209 Amazon Linux Security Advisory for libxml2 : ALAS2023-2023-096
- 376607 Apple macOS Security Update 2022-004 Catalina (HT213255)
- 376608 Apple MacOS Big Sur 11.6.6 Not Installed (HT213256)
- 376612 Apple macOS Monterey 12.4 Not Installed (HT213257)
- 377365 Alibaba Cloud Linux Security Update for libxml2 (ALINUX3-SA-2022:0018)
- 377726 F5 BIG-IP Libxml2 vulnerability cve-2022-23308 (K32760744)
- 377937 Splunk Enterprise Multiple Vulnerabilities (svd-2022-0804)
- 500344 Alpine Linux Security Update for libxml2
- 502932 Alpine Linux Security Update for qt5-qtwebengine
- 503231 Alpine Linux Security Update for qt5-qtwebengine
- 504107 Alpine Linux Security Update for libxml2
- 506188 Alpine Linux Security Update for qt5-qtwebengine
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 610416 Apple iOS 15.5 and iPadOS 15.5 Security Update Missing (HT213258)
- 6120010 Google COS Security Update for dev-libs/libxml2 (CVE-2022-23308)
- 671562 EulerOS Security Update for libxml2 (EulerOS-SA-2022-1574)
- 671602 EulerOS Security Update for libxml2 (EulerOS-SA-2022-1541)
- 671675 EulerOS Security Update for libxml2 (EulerOS-SA-2022-1741)
- 671744 EulerOS Security Update for libxml2 (EulerOS-SA-2022-1810)
- 671750 EulerOS Security Update for libxml2 (EulerOS-SA-2022-1793)
- 671794 EulerOS Security Update for libxml2 (EulerOS-SA-2022-1870)
- 671803 EulerOS Security Update for libxml2 (EulerOS-SA-2022-1846)
- 710642 Gentoo Linux libxml2 Multiple Vulnerabilities (GLSA 202210-03)
- 751855 SUSE Enterprise Linux Security Update for python-libxml2-python (SUSE-SU-2022:0802-1)
- 751859 OpenSUSE Security Update for python-libxml2-python (openSUSE-SU-2022:0802-1)
- 752068 SUSE Enterprise Linux Security Update for libxml2 (SUSE-SU-2022:1308-1)
- 752156 SUSE Enterprise Linux Security Update for libxml2 (SUSE-SU-2022:1750-1)
- 752389 SUSE Enterprise Linux Security Update for libxml2 (SUSE-SU-2022:2552-1)
- 753147 SUSE Enterprise Linux Security Update for libxml2 (SUSE-SU-2022:14904-1)
- 900725 Common Base Linux Mariner (CBL-Mariner) Security Update for libxml2 (8851)
- 901008 Common Base Linux Mariner (CBL-Mariner) Security Update for libxml2 (8862-1)
- 940468 AlmaLinux Security Update for libxml2 (ALSA-2022:0899)
- 960820 Rocky Linux Security Update for libxml2 (RLSA-2022:0899)