NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-python3-lxml | Nov 21, 2022 | Jul 5, 2022 | |
| Alpine Linux | alpine-linux-upgrade-libxml2alpine-linux-upgrade-py3-lxml | Aug 22, 2024 | Jul 5, 2022 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-python3-lxmlamazon-linux-2023-upgrade-python3-lxml-debuginfoamazon-linux-2023-upgrade-python-lxml-debugsource | Feb 17, 2025 | Jul 5, 2022 | |
| Centos_linux | — | centos-upgrade-python-lxml-debugsourcecentos-upgrade-python3-lxmlcentos-upgrade-python3-lxml-debuginfo | Nov 16, 2022 | Jul 5, 2022 |
| Debian | debian-upgrade-libxml2debian-upgrade-lxml | Jul 30, 2024 | Jul 5, 2022 | |
| Dell Powerstore Dsa2024158 | dell-powerstoreos-upgrade-latest | Jan 13, 2026 | Apr 4, 2024 | |
| Dell Powerstore Dsa2024225 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | May 29, 2024 | |
| Dell Powerstore Dsa2024462 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | Nov 20, 2024 | |
| Dell Powerstore Dsa2024497 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | Dec 19, 2024 | |
| Dell Powerstore Dsa2025050 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | Jan 28, 2025 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-python-lxml | Aug 11, 2022 | Jul 5, 2022 | |
| Huawei Euleros 2_0_sp10 | huawei-euleros-2_0_sp10-upgrade-libxml2huawei-euleros-2_0_sp10-upgrade-python3-libxml2 | Nov 3, 2022 | Jul 5, 2022 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-python-lxml | Oct 11, 2022 | Jul 5, 2022 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-python2-lxmlhuawei-euleros-2_0_sp8-upgrade-python3-lxml | Oct 11, 2022 | Jul 5, 2022 | |
| Huawei Euleros 2_0_sp9 | huawei-euleros-2_0_sp9-upgrade-libxml2huawei-euleros-2_0_sp9-upgrade-python3-libxml2 | Sep 14, 2022 | Jul 5, 2022 | |
| Oracle_linux | — | oracle-linux-upgrade-python3-lxml | Nov 22, 2022 | Jul 5, 2022 |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-python-lxml-debugsourceredhat-upgrade-python3-lxmlredhat-upgrade-python3-lxml-debuginfo | Nov 16, 2022 | Jul 5, 2022 | |
| Rocky_linux | rocky-upgrade-python3-lxmlrocky-upgrade-python3-lxml-debuginfo | Mar 12, 2024 | Jul 5, 2022 | |
| Splunk | splunk-upgrade-latest | Sep 30, 2025 | Jul 5, 2022 | |
| Suse | — | suse-upgrade-libxml2-2suse-upgrade-libxml2-2-32bitsuse-upgrade-libxml2-develsuse-upgrade-libxml2-toolssuse-upgrade-python2-lxmlsuse-upgrade-python2-lxml-develsuse-upgrade-python3-libxml2suse-upgrade-python3-lxmlsuse-upgrade-python3-lxml-develsuse-upgrade-python3-lxml-doc | Oct 26, 2022 | Jul 5, 2022 |
| Ubuntu | ubuntu-upgrade-libxml2ubuntu-upgrade-libxml2-utils | Dec 5, 2022 | Jul 5, 2022 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Jul 5, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub