In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libxml2 | Xmlsoft | * | 2.13.8 (excluding) |
| Libxml2 | Xmlsoft | 2.14.0 (including) | 2.14.2 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | libxml2-0:2.12.5-9.el10_0 | * |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | RedHat | libxml2-0:2.9.1-6.el7_9.13 | * |
| Red Hat Enterprise Linux 8 | RedHat | libxml2-0:2.9.7-21.el8_10.3 | * |
| Red Hat Enterprise Linux 8 | RedHat | libxml2-0:2.9.7-21.el8_10.3 | * |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | RedHat | libxml2-0:2.9.7-9.el8_2.5 | * |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | libxml2-0:2.9.7-9.el8_4.8 | * |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | RedHat | libxml2-0:2.9.7-9.el8_4.8 | * |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | RedHat | libxml2-0:2.9.7-13.el8_6.12 | * |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | RedHat | libxml2-0:2.9.7-13.el8_6.12 | * |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | RedHat | libxml2-0:2.9.7-13.el8_6.12 | * |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | RedHat | libxml2-0:2.9.7-16.el8_8.12 | * |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | RedHat | libxml2-0:2.9.7-16.el8_8.12 | * |
| Red Hat Enterprise Linux 9 | RedHat | libxml2-0:2.9.13-12.el9_6 | * |
| Red Hat Enterprise Linux 9 | RedHat | libxml2-0:2.9.13-12.el9_6 | * |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | RedHat | libxml2-0:2.9.13-1.el9_0.7 | * |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | libxml2-0:2.9.13-3.el9_2.9 | * |
| Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | libxml2-0:2.9.13-12.el9_4 | * |
| Red Hat JBoss Core Services 2.4.62.SP1 | RedHat | libxml2 | * |
| Red Hat OpenShift Container Platform 4.12 | RedHat | rhcos-412.86.202509030110-0 | * |
| Red Hat OpenShift Container Platform 4.13 | RedHat | rhcos-413.92.202509030117-0 | * |
| Red Hat OpenShift Container Platform 4.14 | RedHat | rhcos-414.92.202508270040-0 | * |
| Red Hat OpenShift Container Platform 4.15 | RedHat | rhcos-415.92.202509170209-0 | * |
| Red Hat OpenShift Container Platform 4.16 | RedHat | rhcos-416.94.202508261955-0 | * |
| Red Hat OpenShift Container Platform 4.17 | RedHat | rhcos-417.94.202508141510-0 | * |
| Red Hat OpenShift Container Platform 4.18 | RedHat | rhcos-418.94.202508261658-0 | * |
| Red Hat OpenShift Container Platform 4.19 | RedHat | rhcos-4.19.9.6.202508271124-0 | * |
| Red Hat Ceph Storage 7 | RedHat | rhceph/rhceph-7-rhel9:sha256:4d2f9dc5b2b33ee1c77bbfabcbbb9f4d94d343b04c4de2e4f8b3b81a1f0fd2fe | * |
| Red Hat Discovery 2 | RedHat | discovery/discovery-server-rhel9:sha256:6464f1f591001fd514a87e3c7347d2ce709b9c97edaad2d0d649ae69499049e9 | * |
| Red Hat Insights proxy 1.5 | RedHat | insights-proxy/insights-proxy-container-rhel9:sha256:3fa6c89778502bfb0b16ef8ff3c576467e8a21269afb2380c4ae176ee2fc7fec | * |
| Red Hat OpenShift distributed tracing 3.5.2 | RedHat | rhosdt/jaeger-agent-rhel8:sha256:a3e7ac42823a2f58d15b52b5c729ae34f3e119122fb4defae4754e6ab14dabcd | * |
| Red Hat OpenShift distributed tracing 3.5.2 | RedHat | rhosdt/jaeger-all-in-one-rhel8:sha256:1ed7ca9ba1fe229bb04b4b59b0a7161286786c025d5dbe688d3e68e0af85945b | * |
| Red Hat OpenShift distributed tracing 3.5.2 | RedHat | rhosdt/jaeger-collector-rhel8:sha256:593c9e2656e624b444bd45740c6e556c06137ab6cf7aaa0387799b10669b74e9 | * |
| Red Hat OpenShift distributed tracing 3.5.2 | RedHat | rhosdt/jaeger-es-index-cleaner-rhel8:sha256:c56438a8b89d2c25209e3b50a6d45e050c26b514179d0781e7ee223f32dce7d2 | * |
| Red Hat OpenShift distributed tracing 3.5.2 | RedHat | rhosdt/jaeger-es-rollover-rhel8:sha256:a49b8de5c60cd6af7fd0d70fbf0c7e9ae0b4e26eebe2ed2b4490e756ff07fa9c | * |
| Red Hat OpenShift distributed tracing 3.5.2 | RedHat | rhosdt/jaeger-ingester-rhel8:sha256:453d643c17511e3e981706e5ba5b88ee8df3334dc38232ecb2069f67e269cc8b | * |
| Red Hat OpenShift distributed tracing 3.5.2 | RedHat | rhosdt/jaeger-operator-bundle:sha256:264613b2add0f32e5f537ee7cf9ba8019e5e9a347fdf20bc3de8d1678157ba66 | * |
| Red Hat OpenShift distributed tracing 3.5.2 | RedHat | rhosdt/jaeger-query-rhel8:sha256:43ce372ddc2de4dc633322ec84fca9927d5a6649068f58cfaa238de39d03a0d2 | * |
| Red Hat OpenShift distributed tracing 3.5.2 | RedHat | rhosdt/jaeger-rhel8-operator:sha256:c6f9ee5f306766c0502419fe691e9e14aad8b0d1a4ced7ff9b1738c272fba80b | * |
| Libxml2 | Ubuntu | devel | * |
| Libxml2 | Ubuntu | esm-infra-legacy/trusty | * |
| Libxml2 | Ubuntu | esm-infra/bionic | * |
| Libxml2 | Ubuntu | esm-infra/focal | * |
| Libxml2 | Ubuntu | esm-infra/xenial | * |
| Libxml2 | Ubuntu | focal | * |
| Libxml2 | Ubuntu | jammy | * |
| Libxml2 | Ubuntu | noble | * |
| Libxml2 | Ubuntu | oracular | * |
| Libxml2 | Ubuntu | plucky | * |
| Libxml2 | Ubuntu | questing | * |
| Libxml2 | Ubuntu | upstream | * |
Specified quantities include size, length, frequency, price, rate, number of operations, time, and others. Code may rely on specified quantities to allocate resources, perform calculations, control iteration, etc.