vulnerability

Amazon Linux 2023: CVE-2022-23308: Medium priority package update for libxml2

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
Feb 20, 2022
Added
Feb 17, 2025
Modified
Jul 4, 2025

Description

valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
A flaw was found in libxml2. A call to the xmlGetID function can return a pointer already freed when parsing an XML document with the XML_PARSE_DTDVALID option and without the XML_PARSE_NOENT option, resulting in a use-after-free issue.

Solutions

amazon-linux-2023-upgrade-libxml2amazon-linux-2023-upgrade-libxml2-debuginfoamazon-linux-2023-upgrade-libxml2-debugsourceamazon-linux-2023-upgrade-libxml2-develamazon-linux-2023-upgrade-libxml2-staticamazon-linux-2023-upgrade-python3-libxml2amazon-linux-2023-upgrade-python3-libxml2-debuginfo
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.