First published: Tue Jun 28 2022(Updated: )
The libxml2 library is a development toolbox providing the implementation of various XML standards.<br>Security Fix(es):<br><li> libxml2: integer overflows in xmlBuf and xmlBuffer lead to out-of-bounds write (CVE-2022-29824)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libxml2 | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/libxml2 | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/libxml2-debuginfo | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/libxml2-debuginfo | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/libxml2-debugsource | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/libxml2-debugsource | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/libxml2-devel | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/libxml2-devel | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/python3-libxml2 | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/python3-libxml2-debuginfo | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/python3-libxml2-debuginfo | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/python3-libxml2 | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/libxml2 | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/libxml2-debuginfo | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/libxml2-debugsource | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/libxml2-devel | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/python3-libxml2 | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/python3-libxml2-debuginfo | <2.9.7-13.el8_6.1 | 2.9.7-13.el8_6.1 |
redhat/libxml2 | <2.9.7-13.el8_6.1.aa | 2.9.7-13.el8_6.1.aa |
redhat/libxml2-debuginfo | <2.9.7-13.el8_6.1.aa | 2.9.7-13.el8_6.1.aa |
redhat/libxml2-debugsource | <2.9.7-13.el8_6.1.aa | 2.9.7-13.el8_6.1.aa |
redhat/libxml2-devel | <2.9.7-13.el8_6.1.aa | 2.9.7-13.el8_6.1.aa |
redhat/python3-libxml2 | <2.9.7-13.el8_6.1.aa | 2.9.7-13.el8_6.1.aa |
redhat/python3-libxml2-debuginfo | <2.9.7-13.el8_6.1.aa | 2.9.7-13.el8_6.1.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:5317 is classified as moderate.
To fix RHSA-2022:5317, update the libxml2 package to version 2.9.7-13.el8_6.1 or later.
RHSA-2022:5317 addresses integer overflows in xmlBuf and xmlBuffer that lead to out-of-bounds write vulnerabilities.
Affected packages in RHSA-2022:5317 include libxml2, libxml2-devel, python3-libxml2, and their debuginfo variants.
The RHSA-2022:5317 advisory was released on December 20, 2022.