Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Slackware: 2022-059-01 Critical Update for Libxml2 Memory Issues

slackware
Calendar Grey March 1, 2022
Dist Slackware Esm H88
Updated libxml2 packages released for Slackware to address severe security vulnerabilities involving memory corruption and null pointer dereferences.
New libxml2 packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues

Summary

Here are the details from the Slackware 15.0 ChangeLog: patches/packages/libxml2-2.9.13-i586-1_slack15.0.txz: Upgraded. This update fixes bugs and the following security issues: Use-after-free of ID and IDREF attributes (Thanks to Shinji Sato for the report) Use-after-free in xmlXIncludeCopyRange (David Kilzer) Fix Null-deref-in-xmlSchemaGetComponentTargetNs (huangduirong) Fix memory leak in xmlXPathCompNodeTest Fix null pointer deref in xmlStringGetNodeList Fix several memory leaks found by Coverity (David King) For more information, see: https://www.cve.org/CVERecord?id=CVE-2022-23308 (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 14.0:
Updated package for Slackware x86_64 14.0:
Updated package for Slackware 14.1:
Updated package for Slackware x86_64 14.1:
Updated package for Slackware 14.2:
Updated package for Slackware x86_64 14.2:
Updated package for Slackware 15.0:
Updated package for Slackware x86_64 15.0:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 14.0 package: 889493500cae59856e974769aad5cacd libxml2-2.9.13-i486-1_slack14.0.txz
Slackware x86_64 14.0 package: 69bd45c994ccca1449264142808a9281 libxml2-2.9.13-x86_64-1_slack14.0.txz
Slackware 14.1 package: 3044c808e30600d32a0f0995b201b72b libxml2-2.9.13-i486-1_slack14.1.txz
Slackware x86_64 14.1 package: 960fae9906a6d5bc39eff393f9d34f07 libxml2-2.9.13-x86_64-1_slack14.1.txz
Slackware 14.2 package: c0158c620e67597a059254f029b89f95 libxml2-2.9.13-i586-1_slack14.2.txz
Slackware x86_64 14.2 package: 42310887af04b0c4a41d6ac1058b55ea libxml2-2.9.13-x86_64-1_slack14.2.txz
Slackware 15.0 package: edb73cc40d01801e0983698f517338b6 libxml2-2.9.13-i586-1_slack15.0.txz
Slackware x86_64 15.0 package: 0bbced56311b6ccf66461752ea249d52 libxml2-2.9.13-x86_64-1_slack15.0.txz
Slackware -current package: 00849e22225c74466add9933bc36a3ae l/libxml2-2.9.13-i586-1.txz
Slackware x86_64 -current package: 8074609ef54039cc832da702bdeb660e l/libxml2-2.9.13-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg libxml2-2.9.13-i586-1_slack15.0.txz

Related News

Your message here