REDHAT-BUG-2346416: Use After Free
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2346416?
REDHAT-BUG-2346416 is classified as a high severity vulnerability due to a use-after-free flaw in libxml2.
How do I fix REDHAT-BUG-2346416?
To mitigate REDHAT-BUG-2346416, upgrade libxml2 to versions 2.12.10 or 2.13.6 or later.
What are the symptoms of exploitation of REDHAT-BUG-2346416?
Exploitation of REDHAT-BUG-2346416 may lead to crashes or unexpected behavior when processing crafted XML documents.
Which versions of libxml2 are affected by REDHAT-BUG-2346416?
Versions of libxml2 before 2.12.10 and 2.13.x prior to 2.13.6 are affected by REDHAT-BUG-2346416.
What components are involved in the vulnerability REDHAT-BUG-2346416?
The components involved in REDHAT-BUG-2346416 are xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c.