CVE-2022-29824
Summary
| CVE | CVE-2022-29824 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-03 03:15:00 UTC |
| Updated | 2023-11-07 03:46:00 UTC |
| Description | In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| libxml2: Multiple Vulnerabilities (GLSA 202210-03) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Tags · GNOME / libxslt · GitLab |
MISC |
gitlab.gnome.org |
|
| [SECURITY] Fedora 36 Update: libxml2-2.9.14-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE-2022-29824 Libxml2 Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [CVE-2022-29824] Fix integer overflows in xmlBuf and xmlBuffer (2554a240) · Commits · GNOME / libxml2 · GitLab |
MISC |
gitlab.gnome.org |
|
| [SECURITY] Fedora 34 Update: libxml2-2.9.14-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| libxml2 xmlBufAdd Heap Buffer Overflow ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| libxml2 xmlParseNameComplex Integer Overflow ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| [SECURITY] Fedora 36 Update: libxml2-2.9.14-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| v2.9.14 · Tags · GNOME / libxml2 · GitLab |
MISC |
gitlab.gnome.org |
|
| [SECURITY] Fedora 34 Update: libxml2-2.9.14-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: libxml2-2.9.14-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: libxml2-2.9.14-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Debian -- Security Information -- DSA-5142-1 libxml2 |
DEBIAN |
www.debian.org |
|
| [SECURITY] [DLA 3012-1] libxml2 security update |
MLIST |
lists.debian.org |
|
| [CVE-2022-29824] Fix integer overflows in xmlBuf and xmlBuffer (6c283d83) · Commits · GNOME / libxml2 · GitLab |
MISC |
gitlab.gnome.org |
|
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159939 Oracle Enterprise Linux Security Update for libxml2 (ELSA-2022-5250)
- 159950 Oracle Enterprise Linux Security Update for libxml2 (ELSA-2022-5317)
- 179291 Debian Security Update for libxml2 (DLA 3012-1)
- 179303 Debian Security Update for libxml2 (DSA 5142-1)
- 183660 Debian Security Update for libxml2 (CVE-2022-29824)
- 198787 Ubuntu Security Notification for libxml2 Vulnerabilities (USN-5422-1)
- 240498 Red Hat Update for libxml2 (RHSA-2022:5250)
- 240522 Red Hat Update for libxml2 (RHSA-2022:5317)
- 282682 Fedora Security Update for libxml2 (FEDORA-2022-be6d83642a)
- 282715 Fedora Security Update for libxml2 (FEDORA-2022-f624aad735)
- 282717 Fedora Security Update for libxml2 (FEDORA-2022-9136d646e4)
- 330110 IBM AIX Denial of Service (DoS) Vulnerability in libxml2 (libxml2_advisory3)
- 354066 Amazon Linux Security Advisory for libxml2 : ALAS2-2022-1848
- 354464 Amazon Linux Security Advisory for libxml2 : ALAS2022-2022-198
- 354486 Amazon Linux Security Advisory for libxml2 : ALAS2022-2022-068
- 354638 Amazon Linux Security Advisory for libxml2 : AL2012-2022-370
- 354929 Amazon Linux Security Advisory for libxml2 : ALAS-2023-1743
- 355209 Amazon Linux Security Advisory for libxml2 : ALAS2023-2023-096
- 377359 Alibaba Cloud Linux Security Update for libxml2 (ALINUX3-SA-2022:0127)
- 377911 Oracle Hypertext Transfer Protocol Server (HTTP Server) Multiple Vulnerabilities (CPUJAN2023)
- 377937 Splunk Enterprise Multiple Vulnerabilities (svd-2022-0804)
- 500345 Alpine Linux Security Update for libxml2
- 504108 Alpine Linux Security Update for libxml2
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 671850 EulerOS Security Update for libxml2 (EulerOS-SA-2022-1901)
- 671876 EulerOS Security Update for libxml2 (EulerOS-SA-2022-1938)
- 671903 EulerOS Security Update for libxml2 (EulerOS-SA-2022-2002)
- 671959 EulerOS Security Update for libxml2 (EulerOS-SA-2022-1972)
- 671967 EulerOS Security Update for libxml2 (EulerOS-SA-2022-2137)
- 672007 EulerOS Security Update for libxml2 (EulerOS-SA-2022-2162)
- 672243 EulerOS Security Update for libxml2 (EulerOS-SA-2022-2622)
- 710642 Gentoo Linux libxml2 Multiple Vulnerabilities (GLSA 202210-03)
- 752156 SUSE Enterprise Linux Security Update for libxml2 (SUSE-SU-2022:1750-1)
- 752169 SUSE Enterprise Linux Security Update for libxml2 (SUSE-SU-2022:1833-1)
- 752389 SUSE Enterprise Linux Security Update for libxml2 (SUSE-SU-2022:2552-1)
- 753947 SUSE Enterprise Linux Security Update for libxml2 (SUSE-SU-2023:2048-1)
- 901287 Common Base Linux Mariner (CBL-Mariner) Security Update for libxslt (9624)
- 901292 Common Base Linux Mariner (CBL-Mariner) Security Update for libxml2 (9623)
- 901759 Common Base Linux Mariner (CBL-Mariner) Security Update for libxml2 (9616)
- 901864 Common Base Linux Mariner (CBL-Mariner) Security Update for libxslt (9617)
- 902128 Common Base Linux Mariner (CBL-Mariner) Security Update for libxml2 (9616-1)
- 902494 Common Base Linux Mariner (CBL-Mariner) Security Update for libxml2 (9623-1)
- 904809 Common Base Linux Mariner (CBL-Mariner) Security Update for libxslt (9624-1)
- 906229 Common Base Linux Mariner (CBL-Mariner) Security Update for libxslt (9624-2)
- 906305 Common Base Linux Mariner (CBL-Mariner) Security Update for libxslt (9617-2)
- 960298 Rocky Linux Security Update for libxml2 (RLSA-2022:5317)
- 960613 Rocky Linux Security Update for libxml2 (RLSA-2022:5250)