An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python3-libxml2Upgrade libxml2Upgrade libxml2-devel | Jan 17, 2023 | Nov 23, 2022 |
| Alpine Linux | — | Upgrade libxml2 | Mar 26, 2024 | Nov 22, 2022 |
| Amazon Linux Ami 2 | — | Upgrade libxml2-pythonUpgrade libxml2-staticUpgrade libxml2Upgrade libxml2-develUpgrade libxml2-debuginfo | Mar 22, 2023 | Nov 23, 2022 |
| Amazon_linux | — | Upgrade libxml2 | May 4, 2023 | Oct 22, 2022 |
| Amazon_linux_2023 | — | Upgrade python3-libxml2Upgrade xmlsec1-debuginfoUpgrade xmlsec1-openssl-debuginfoUpgrade xmlsec1-debugsourceUpgrade libxml2-staticUpgrade xmlsec1-develUpgrade python3-libxml2-debuginfoUpgrade libxml2-develUpgrade xmlsec1-openssl-develUpgrade xmlsec1Upgrade xmlsec1-opensslUpgrade libxml2-debuginfoUpgrade libxml2Upgrade libxml2-debugsource | Feb 17, 2025 | Oct 14, 2022 |
| Apple Osx Libxml2 | — | Upgrade macOS to the latest version | Nov 10, 2022 | Nov 10, 2022 |
| Centos_linux | — | Upgrade libxml2-debuginfoUpgrade libxml2-develUpgrade libxml2-debugsourceUpgrade python3-libxml2-debuginfoUpgrade python3-libxml2Upgrade libxml2 | Jan 17, 2023 | Nov 23, 2022 |
| Debian | — | Upgrade libxml2 | Nov 1, 2022 | Nov 1, 2022 |
| Dell Powerstore Dsa2023173 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jun 21, 2023 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Nov 1, 2022 | Oct 31, 2022 |
| Huawei Euleros 2_0_sp10 | — | Upgrade python3-libxml2Upgrade libxml2 | Feb 13, 2023 | Nov 23, 2022 |
| Huawei Euleros 2_0_sp11 | — | Upgrade libxml2Upgrade python3-libxml2 | Jan 6, 2023 | Nov 23, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libxml2-develUpgrade libxml2-pythonUpgrade libxml2 | Mar 9, 2023 | Nov 23, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade libxml2-develUpgrade libxml2Upgrade python3-libxml2Upgrade python2-libxml2 | Dec 9, 2022 | Nov 23, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade python3-libxml2Upgrade libxml2 | Jan 9, 2023 | Nov 23, 2022 |
| Ibm Aix | — | Apply the fix or workaround for libxml2_advisory4 | Feb 9, 2023 | Nov 23, 2022 |
| Oracle_linux | — | Upgrade libxml2Upgrade libxml2-develUpgrade python3-libxml2 | Jan 17, 2023 | Oct 14, 2022 |
| Redhat_linux | — | No solution existsUpgrade python3-libxml2Upgrade python3-libxml2-debuginfoUpgrade libxml2-debugsourceUpgrade libxml2Upgrade libxml2-debuginfoUpgrade libxml2-devel | Jan 17, 2023 | Nov 23, 2022 |
| Rocky_linux | — | Upgrade libxml2-develUpgrade libxml2-debuginfoUpgrade python3-libxml2-debuginfoUpgrade libxml2Upgrade libxml2-debugsourceUpgrade python3-libxml2 | Mar 12, 2024 | Nov 23, 2022 |
| Splunk | — | Upgrade Splunk Enterprise to version 8.2.11Upgrade Splunk Universal Forwarder to version 9.0.5Upgrade Splunk Universal Forwarder to version 8.2.11Upgrade Splunk Enterprise to version 9.0.5Upgrade Splunk Enterprise to version 8.1.14Upgrade Splunk Universal Forwarder to version 8.1.14 | Sep 30, 2025 | Nov 22, 2022 |
| Suse | — | Upgrade libxml2-docUpgrade python3-libxml2-pythonUpgrade libxml2-devel-32bitUpgrade python-libxml2Upgrade libxml2-develUpgrade libxml2-2-32bitUpgrade python2-libxml2-pythonUpgrade python3-libxml2Upgrade libxml2-toolsUpgrade libxml2-2 | Oct 26, 2022 | Oct 22, 2022 |
| Ubuntu | — | Upgrade ruby-nokogiri (Ubuntu Pro)Upgrade libxml2-utils (Ubuntu Pro)Upgrade libxml2Upgrade libxml2-utilsUpgrade libxml2 (Ubuntu Pro) | Dec 5, 2022 | Oct 22, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Nov 22, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub