Описание
In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
A flaw in libxml2's xmlXPtrEvalXPtrPart function allows a local attacker to cause a heap-based buffer overflow. An integer overflow while processing an oversized xpointer() expression leads to incorrect memory allocation and an out-of-bounds write, potentially resulting in information disclosure, data corruption, or a denial of service (DoS).
Отчет
A heap-based buffer overflow in libxml2's xmlXPtrEvalXPtrPart function enables an out-of-bounds write during the evaluation of oversized xpointer() expressions. The flaw is assigned a Moderate severity rating because exploitation strictly requires local access and complex, multi-gigabyte payload inputs, effectively mitigating the threat of remote or automated system compromise.
Меры по смягчению последствий
To mitigate this applications should avoid passing untrusted XPointer expressions into xmlXPtrEval or XInclude xpointer= attributes and strictly cap input length well below INT_MAX. Additionally, administrators should enforce process or cgroup memory limits to prevent the construction of multi-gigabyte scheme bodies, relying on heap allocator hardening rather than standard fortify flags, which cannot stop this byte-store loop.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libxml2 | Affected | ||
| Red Hat Enterprise Linux 10 | podman | Not affected | ||
| Red Hat Enterprise Linux 6 | libxml2 | Not affected | ||
| Red Hat Enterprise Linux 7 | libxml2 | Not affected | ||
| Red Hat Enterprise Linux 8 | container-tools:rhel8/podman | Not affected | ||
| Red Hat Enterprise Linux 8 | libxml2 | Not affected | ||
| Red Hat Enterprise Linux 9 | libxml2 | Fix deferred | ||
| Red Hat Enterprise Linux 9 | podman | Not affected | ||
| Red Hat Hardened Images | swift-lang | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
6.9 Medium
CVSS3
Связанные уязвимости
(In libxml2 before 2.15.4, there is a heap-based buffer overflow in xml ...)
In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
In libxml2 before 2.15.4, there is a heap-based buffer overflow in xml ...
In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
6.9 Medium
CVSS3