Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 9: MGASA-2024-0172 Critical: Libxml2 Use-After-Free

mageia
Calendar Grey May 9, 2024
Dist Mageia Esm H88
Mageia has issued a security notice regarding a vulnerability in libxml2 that impacts all versions released before 2.11.7 and 2.12.5.
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5

Summary

An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free. (CVE-2024-25062)

References

- https://bugs.mageia.org/show_bug.cgi?id=33184

- https://lwn.net/Articles/972329/

- https://www.cve.org/CVERecord?id=CVE-2024-25062

Resolution

SRPMS

- 9/core/libxml2-2.10.4-1.3.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 09 May 2024
URL: https://advisories.mageia.org/MGASA-2024-0172.html
Type: security
CVE: CVE-2024-25062

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here