Описание
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
An integer overflow in the libxml2 xmlIO module occurs when data backlogs exceed maximum integer limits. This flaw passes negative length values to downstream write callbacks, creating an unsafe state that can lead to data corruption or compromise application confidentiality and integrity.
Отчет
Moderate impact: This flaw in libxml2, a widely used XML parsing library, is due to an integer overflow in write callbacks. This can lead to negative lengths being passed to write operations, potentially causing data integrity issues in applications that process untrusted XML input and utilize affected write callbacks. The impact is limited to applications that specifically trigger this overflow condition.
Меры по смягчению последствий
Cap process and cgroup memory so a process cannot build a ≥2 GiB libxml2 output backlog. Keep FORTIFY_SOURCE-built Red Hat binaries so some callback copies of the truncated length abort instead of corrupting memory
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libxml2 | Affected | ||
| Red Hat Enterprise Linux 10 | podman | Not affected | ||
| Red Hat Enterprise Linux 6 | libxml2 | Out of support scope | ||
| Red Hat Enterprise Linux 7 | libxml2 | Out of support scope | ||
| Red Hat Enterprise Linux 8 | container-tools:rhel8/podman | Not affected | ||
| Red Hat Enterprise Linux 8 | libxml2 | Fix deferred | ||
| Red Hat Enterprise Linux 9 | libxml2 | Affected | ||
| Red Hat Enterprise Linux 9 | podman | Not affected | ||
| Red Hat Hardened Images | swift-lang | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.9 Medium
CVSS3
Связанные уязвимости
(In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteC ...)
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteC ...
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
EPSS
6.9 Medium
CVSS3