PT-2023-6121 · Libxml2+5 · Libxml2+5

Alan Coopersmith

·

Published

2023-10-06

·

Updated

2025-07-27

·

CVE-2023-45322

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libxml2 versions 2.11.5 and earlier
Description The issue is related to a use-after-free vulnerability in the xmlUnlinkNode function, located in tree.c, which can occur after a certain memory allocation fails. This could potentially allow a remote attacker to cause a denial of service. The vendor has stated that they do not consider this issue critical enough to warrant a fix because an attacker typically cannot control when memory allocations fail.
Recommendations For libxml2 versions 2.11.5 and earlier, as a temporary workaround, consider disabling the xmlUnlinkNode function until a patch is available. Restrict access to the tree.c module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2023-8083
AZL-31272
AZL-34960
BDU:2023-06827
CVE-2023-45322
DLA-4064-1
DSA-5949-1
ECHO-86F2-08FD-B895
MGASA-2023-0298
OESA-2023-1742
OPENSUSE-SU-2023_4464-1
OPENSUSE-SU-2023_4504-1
OPENSUSE-SU-2023_4537-1
OPENSUSE-SU-2024:13426-1
ROSA-SA-2024-2467
SUSE-SU-2023:4464-1
SUSE-SU-2023:4504-1
SUSE-SU-2023:4505-1
SUSE-SU-2023:4537-1
SUSE-SU-2023_4504-1
SUSE-SU-2023_4505-1
SUSE-SU-2023_4537-1

Affected Products

Alt Linux
Astra Linux
Debian
Red Os
Suse
Libxml2