In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libxml2 | Xmlsoft | * | 2.13.8 (excluding) |
| Libxml2 | Xmlsoft | 2.14.0 (including) | 2.14.2 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | libxml2-0:2.12.5-9.el10_0 | * |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | RedHat | libxml2-0:2.9.1-6.el7_9.13 | * |
| Red Hat Enterprise Linux 8 | RedHat | libxml2-0:2.9.7-21.el8_10.3 | * |
| Red Hat Enterprise Linux 8 | RedHat | libxml2-0:2.9.7-21.el8_10.3 | * |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | RedHat | libxml2-0:2.9.7-9.el8_2.5 | * |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | libxml2-0:2.9.7-9.el8_4.8 | * |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | RedHat | libxml2-0:2.9.7-9.el8_4.8 | * |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | RedHat | libxml2-0:2.9.7-13.el8_6.12 | * |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | RedHat | libxml2-0:2.9.7-13.el8_6.12 | * |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | RedHat | libxml2-0:2.9.7-13.el8_6.12 | * |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | RedHat | libxml2-0:2.9.7-16.el8_8.12 | * |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | RedHat | libxml2-0:2.9.7-16.el8_8.12 | * |
| Red Hat Enterprise Linux 9 | RedHat | libxml2-0:2.9.13-12.el9_6 | * |
| Red Hat Enterprise Linux 9 | RedHat | libxml2-0:2.9.13-12.el9_6 | * |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | RedHat | libxml2-0:2.9.13-1.el9_0.7 | * |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | libxml2-0:2.9.13-3.el9_2.9 | * |
| Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | libxml2-0:2.9.13-12.el9_4 | * |
| Red Hat JBoss Core Services 2.4.62.SP1 | RedHat | libxml2 | * |
| Red Hat OpenShift Container Platform 4.12 | RedHat | rhcos-412.86.202509030110-0 | * |
| Red Hat OpenShift Container Platform 4.13 | RedHat | rhcos-413.92.202509030117-0 | * |
| Red Hat OpenShift Container Platform 4.14 | RedHat | rhcos-414.92.202508270040-0 | * |
| Red Hat OpenShift Container Platform 4.15 | RedHat | rhcos-415.92.202509170209-0 | * |
| Red Hat OpenShift Container Platform 4.16 | RedHat | rhcos-416.94.202508261955-0 | * |
| Red Hat OpenShift Container Platform 4.17 | RedHat | rhcos-417.94.202508141510-0 | * |
| Red Hat OpenShift Container Platform 4.18 | RedHat | rhcos-418.94.202508261658-0 | * |
| Red Hat OpenShift Container Platform 4.19 | RedHat | rhcos-4.19.9.6.202508271124-0 | * |
| Red Hat Ceph Storage 7 | RedHat | rhceph/rhceph-7-rhel9:sha256:6b79ed10423d954d21dd24c9cb1cf507f6e02c2942ace7fa30cf7af2ffaeb631 | * |
| Red Hat Discovery 2 | RedHat | discovery/discovery-server-rhel9:sha256:7d200c5dcd40e0885171fe20e3edb5d432a8675080846fb3ba273c601c5957a1 | * |
| Red Hat Insights proxy 1.5 | RedHat | insights-proxy/insights-proxy-container-rhel9:sha256:b7f671263af799e681ccca9b07420c1b5cee369282b5e1520557ee2414618652 | * |
| Red Hat OpenShift distributed tracing 3.5.1 | RedHat | rhosdt/jaeger-agent-rhel8:sha256:ef10956a206329b8213fb31855fbcc849d00e1e44adb307985009be2bfdb966e | * |
| Red Hat OpenShift distributed tracing 3.5.1 | RedHat | rhosdt/jaeger-all-in-one-rhel8:sha256:57ef3d922681abc67745773f5f7232b23038767b05b5b4c713c3b5089ea9e295 | * |
| Red Hat OpenShift distributed tracing 3.5.1 | RedHat | rhosdt/jaeger-collector-rhel8:sha256:6f60741c03460bfdc70789640b83b8c2611f62bd3971a7eeb8316c895e4cbf48 | * |
| Red Hat OpenShift distributed tracing 3.5.1 | RedHat | rhosdt/jaeger-es-index-cleaner-rhel8:sha256:deb807f053dacbbea6e950e13ee123bb8b9184e0d8eca0d04d5e8f48d3ef6a95 | * |
| Red Hat OpenShift distributed tracing 3.5.1 | RedHat | rhosdt/jaeger-es-rollover-rhel8:sha256:39b2d56b8f0eb3b539697fc387ae84230182c7e8cf5c184b8ee6c02e29386120 | * |
| Red Hat OpenShift distributed tracing 3.5.1 | RedHat | rhosdt/jaeger-ingester-rhel8:sha256:453d643c17511e3e981706e5ba5b88ee8df3334dc38232ecb2069f67e269cc8b | * |
| Red Hat OpenShift distributed tracing 3.5.1 | RedHat | rhosdt/jaeger-operator-bundle:sha256:264613b2add0f32e5f537ee7cf9ba8019e5e9a347fdf20bc3de8d1678157ba66 | * |
| Red Hat OpenShift distributed tracing 3.5.1 | RedHat | rhosdt/jaeger-query-rhel8:sha256:2509c7cc0bdf6d001442d2e83e21925b09a59c4b05eef81e98af93327f6f6c6d | * |
| Red Hat OpenShift distributed tracing 3.5.1 | RedHat | rhosdt/jaeger-rhel8-operator:sha256:f61bf9363bf43e6e6f0156d1c2eeeecef927a46e0940062429a47a058da057ab | * |
| Libxml2 | Ubuntu | devel | * |
| Libxml2 | Ubuntu | esm-infra-legacy/trusty | * |
| Libxml2 | Ubuntu | esm-infra/bionic | * |
| Libxml2 | Ubuntu | esm-infra/focal | * |
| Libxml2 | Ubuntu | esm-infra/xenial | * |
| Libxml2 | Ubuntu | focal | * |
| Libxml2 | Ubuntu | jammy | * |
| Libxml2 | Ubuntu | noble | * |
| Libxml2 | Ubuntu | oracular | * |
| Libxml2 | Ubuntu | plucky | * |
| Libxml2 | Ubuntu | questing | * |
| Libxml2 | Ubuntu | upstream | * |
Specified quantities include size, length, frequency, price, rate, number of operations, time, and others. Code may rely on specified quantities to allocate resources, perform calculations, control iteration, etc.