A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.
The product attempts to return a memory resource to the system, but it calls the wrong release function or calls the appropriate release function incorrectly.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | RedHat | libxml2-0:2.12.5-10.el10_2.4 | * |
| Red Hat Enterprise Linux 8 | RedHat | libxml2-0:2.9.7-21.el8_10.9 | * |
| Red Hat Enterprise Linux 8 | RedHat | libxml2-0:2.9.7-21.el8_10.9 | * |
| Red Hat Enterprise Linux 9 | RedHat | libxml2-0:2.9.13-14.el9_8.5 | * |
| Red Hat Enterprise Linux 9 | RedHat | libxml2-0:2.9.13-14.el9_8.5 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/jetstack-cert-manager-rhel9:1790589912 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/cert-manager-istio-csr-rhel9:1790589914 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/cert-manager-operator-rhel9:1790589855 | * |
| Red Hat Hardened Images | RedHat | libxml2-main-2.15.4-0.1.hum1 | * |
| Libxml2 | Ubuntu | esm-infra-legacy/trusty | * |
| Libxml2 | Ubuntu | esm-infra-legacy/xenial | * |
| Libxml2 | Ubuntu | esm-infra/bionic | * |
| Libxml2 | Ubuntu | esm-infra/focal | * |
| Libxml2 | Ubuntu | jammy | * |
| Libxml2 | Ubuntu | noble | * |
| Libxml2 | Ubuntu | resolute | * |
| Libxml2 | Ubuntu | upstream | * |
This weakness can take several forms, such as: