In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libxml2 | Xmlsoft | * | 2.15.4 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | libxml2-0:2.12.5-10.el10_2.4 | * |
| Red Hat Enterprise Linux 8 | RedHat | libxml2-0:2.9.7-21.el8_10.9 | * |
| Red Hat Enterprise Linux 8 | RedHat | libxml2-0:2.9.7-21.el8_10.9 | * |
| Red Hat Enterprise Linux 9 | RedHat | libxml2-0:2.9.13-14.el9_8.5 | * |
| Red Hat Enterprise Linux 9 | RedHat | libxml2-0:2.9.13-14.el9_8.5 | * |
| Red Hat Hardened Images | RedHat | libxml2-main-2.15.4-0.1.hum1 | * |
| Libxml2 | Ubuntu | upstream | * |