In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
Integer coercion refers to a set of flaws pertaining to the type casting, extension, or truncation of primitive data types.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libxml2 | Xmlsoft | * | 2.15.4 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | libxml2-0:2.12.5-10.el10_2.4 | * |
| Red Hat Enterprise Linux 8 | RedHat | libxml2-0:2.9.7-21.el8_10.9 | * |
| Red Hat Enterprise Linux 8 | RedHat | libxml2-0:2.9.7-21.el8_10.9 | * |
| Red Hat Enterprise Linux 9 | RedHat | libxml2-0:2.9.13-14.el9_8.5 | * |
| Red Hat Enterprise Linux 9 | RedHat | libxml2-0:2.9.13-14.el9_8.5 | * |
| Red Hat Hardened Images | RedHat | libxml2-main-2.15.4-0.1.hum1 | * |
| Libxml2 | Ubuntu | upstream | * |