CVE-2022-40304
Summary
| CVE | CVE-2022-40304 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-23 18:15:00 UTC |
| Updated | 2023-11-07 03:52:00 UTC |
| Description | An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| About the security content of watchOS 9.2 - Apple Support |
CONFIRM |
support.apple.com |
|
| About the security content of iOS 15.7.2 and iPadOS 15.7.2 - Apple Support |
CONFIRM |
support.apple.com |
|
| About the security content of macOS Big Sur 11.7.2 - Apple Support |
CONFIRM |
support.apple.com |
|
| About the security content of macOS Monterey 12.6.2 - Apple Support |
CONFIRM |
support.apple.com |
|
| Full Disclosure: APPLE-SA-2022-12-13-2 iOS 15.7.2 and iPadOS 15.7.2 |
FULLDISC |
seclists.org |
|
| About the security content of tvOS 16.2 - Apple Support |
CONFIRM |
support.apple.com |
|
| Full Disclosure: APPLE-SA-2022-12-13-6 macOS Big Sur 11.7.2 |
FULLDISC |
seclists.org |
|
| Full Disclosure: APPLE-SA-2022-12-13-8 watchOS 9.2 |
|
seclists.org |
|
| Full Disclosure: APPLE-SA-2022-12-13-5 macOS Monterey 12.6.2 |
FULLDISC |
seclists.org |
|
| November 2022 Libxml2 Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [CVE-2022-40304] Fix dict corruption caused by entity reference cycles (1b41ec4e) · Commits · GNOME / libxml2 · GitLab |
MISC |
gitlab.gnome.org |
|
| v2.10.3 · Tags · GNOME / libxml2 · GitLab |
MISC |
gitlab.gnome.org |
|
| Tags · GNOME / libxml2 · GitLab |
MISC |
gitlab.gnome.org |
|
| 20221220 APPLE-SA-2022-12-13-7 tvOS 16.2 |
FULLDISC |
seclists.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160396 Oracle Enterprise Linux Security Update for libxml2 (ELSA-2023-0173)
- 160413 Oracle Enterprise Linux Security Update for libxml2 (ELSA-2023-0338)
- 181179 Debian Security Update for libxml2 (DLA 3172-1)
- 181192 Debian Security Update for libxml2 (DSA 5271-1)
- 183528 Debian Security Update for libxml2 (CVE-2022-40304)
- 199063 Ubuntu Security Notification for libxml2 Vulnerabilities (USN-5760-1)
- 241064 Red Hat Update for libxml2 (RHSA-2023:0173)
- 241093 Red Hat Update for libxml2 (RHSA-2023:0338)
- 242753 Red Hat Update for libxml2 (RHSA-2024:0413)
- 283234 Fedora Security Update for libxml2 (FEDORA-2022-aeafd24818)
- 283465 Fedora Security Update for libxml2 (FEDORA-2022-a6812b0224)
- 330130 IBM AIX Arbitrary Code Execution Vulnerability in libxml2 (libxml2_advisory3)
- 354430 Amazon Linux Security Advisory for libxml2 : ALAS2022-2022-258
- 354487 Amazon Linux Security Advisory for xmlsec1 : ALAS2022-2022-257
- 354559 Amazon Linux Security Advisory for xmlsec1 : ALAS-2022-257
- 354560 Amazon Linux Security Advisory for libxml2 : ALAS-2022-258
- 354834 Amazon Linux Security Advisory for libxml2 : ALAS2-2023-1996
- 354929 Amazon Linux Security Advisory for libxml2 : ALAS-2023-1743
- 355209 Amazon Linux Security Advisory for libxml2 : ALAS2023-2023-096
- 355268 Amazon Linux Security Advisory for xmlsec1 : ALAS2023-2023-097
- 377762 Apple MacOS Ventura 13.0.1 Not Installed (HT213504)
- 377831 Apple macOS Monterey 12.6.2 Not Installed (HT213533)
- 377832 Apple macOS Big Sur 11.7.2 Not Installed (HT213534)
- 377902 Alibaba Cloud Linux Security Update for libxml2 (ALINUX3-SA-2023:0008)
- 378433 Oracle Hypertext Transfer Protocol Server (HTTP Server) Server Multiple Vulnerabilities (CPUAPR2023)
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 502547 Alpine Linux Security Update for libxml2
- 502741 Alpine Linux Security Update for libxml2
- 610450 Apple iOS 16.1.1 and iPadOS 16.1.1 Security Update Missing
- 610455 Apple iOS 15.7.2 and iPadOS 15.7.2 Security Update Missing
- 672422 EulerOS Security Update for libxml2 (EulerOS-SA-2022-2800)
- 672493 EulerOS Security Update for libxml2 (EulerOS-SA-2023-1016)
- 672514 EulerOS Security Update for libxml2 (EulerOS-SA-2023-1041)
- 672550 EulerOS Security Update for libxml2 (EulerOS-SA-2023-1130)
- 672571 EulerOS Security Update for libxml2 (EulerOS-SA-2023-1106)
- 672616 EulerOS Security Update for libxml2 (EulerOS-SA-2023-1393)
- 672665 EulerOS Security Update for libxml2 (EulerOS-SA-2023-1365)
- 672769 EulerOS Security Update for libxml2 (EulerOS-SA-2023-1510)
- 710675 Gentoo Linux libxml2 Multiple Vulnerabilities (GLSA 202210-39)
- 752695 SUSE Enterprise Linux Security Update for libxml2 (SUSE-SU-2022:3692-1)
- 752722 SUSE Enterprise Linux Security Update for libxml2 (SUSE-SU-2022:3717-1)
- 752764 SUSE Enterprise Linux Security Update for libxml2 (SUSE-SU-2022:3871-1)
- 904575 Common Base Linux Mariner (CBL-Mariner) Security Update for libxml2 (11505)
- 904587 Common Base Linux Mariner (CBL-Mariner) Security Update for libxml2 (11500)
- 904623 Common Base Linux Mariner (CBL-Mariner) Security Update for libxml2 (11505-1)
- 904631 Common Base Linux Mariner (CBL-Mariner) Security Update for libxml2 (11500-1)
- 940884 AlmaLinux Security Update for libxml2 (ALSA-2023:0173)
- 940901 AlmaLinux Security Update for libxml2 (ALSA-2023:0338)
- 960535 Rocky Linux Security Update for libxml2 (RLSA-2023:0173)
- 960547 Rocky Linux Security Update for libxml2 (RLSA-2023:0338)