An issue was discovered in libxml2 before 2.11.7 and 2.12.x before
2.12.5. When using the XML Reader interface with DTD validation and
XInclude expansion enabled, processing crafted XML documents can lead to
an xmlValidatePopElement use-after-free. (CVE-2024-25062)
- https://bugs.mageia.org/show_bug.cgi?id=33184
- https://lwn.net/Articles/972329/
- https://www.cve.org/CVERecord?id=CVE-2024-25062
- 9/core/libxml2-2.10.4-1.3.mga9
Get the latest Linux and open source security news straight to your inbox.