CVE-2023-45322: Update xmlsoft/libxml2 to >= v2.11.6
DISPUTED libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail."
Other sources
The xmlsoft/libxml2 version has been upgraded to 2.12.3 to mitigate CVE-2023-45322.
— GitLab
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-45322?
The severity of CVE-2023-45322 is currently disputed by the vendor, as they do not consider it critical.
How do I fix CVE-2023-45322?
To fix CVE-2023-45322, it is recommended to update libxml2 to version 2.11.6 or a later version that resolves the vulnerability.
What type of vulnerability is CVE-2023-45322?
CVE-2023-45322 is a use-after-free vulnerability that occurs during specific memory allocation failures.
Which versions of libxml2 are affected by CVE-2023-45322?
Versions of libxml2 up to and including 2.11.5 are affected by CVE-2023-45322.
Can CVE-2023-45322 be exploited remotely?
The details on the remote exploitability of CVE-2023-45322 are limited, and the vendor has not classified it as critical.