Bug 2342118 (CVE-2022-49043)

Summary: CVE-2022-49043 libxml: use-after-free in xmlXIncludeAddNode
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: adudiak, caswilli, crizzo, csutherl, dfreiber, drow, jburrell, jclere, jmitchel, jtanner, kaycoth, kshier, omaciel, pjindal, plodge, stcannon, szappis, vkumar, vrajput, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in libxml2 where improper handling of memory allocation failures in `libxml2` can lead to crashes, memory leaks, or inconsistent states. While an attacker cannot directly control allocation failures, they may trigger denial-of-service conditions under extreme system stress.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2342194, 2342195, 2342196, 2342197, 2342202, 2342203, 2342204, 2342205, 2342206, 2342198, 2342199, 2342200, 2342201    
Bug Blocks:    

Description OSIDB Bzimport 2025-01-26 06:01:07 UTC
xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.

Comment 3 errata-xmlrpc 2025-02-12 15:23:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:1350 https://access.redhat.com/errata/RHSA-2025:1350

Comment 4 errata-xmlrpc 2025-02-13 20:14:55 UTC
This issue has been addressed in the following products:

  Discovery 1 for RHEL 9

Via RHSA-2025:1487 https://access.redhat.com/errata/RHSA-2025:1487

Comment 7 errata-xmlrpc 2025-02-17 01:25:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2025:1516 https://access.redhat.com/errata/RHSA-2025:1516

Comment 8 errata-xmlrpc 2025-02-17 01:28:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:1517 https://access.redhat.com/errata/RHSA-2025:1517

Comment 9 errata-xmlrpc 2025-02-27 15:19:49 UTC
This issue has been addressed in the following products:

  Service Interconnect 1 for RHEL 9

Via RHSA-2025:1925 https://access.redhat.com/errata/RHSA-2025:1925

Comment 10 errata-xmlrpc 2025-03-10 13:09:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2025:2507 https://access.redhat.com/errata/RHSA-2025:2507

Comment 11 errata-xmlrpc 2025-03-12 11:25:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:2678 https://access.redhat.com/errata/RHSA-2025:2678

Comment 13 errata-xmlrpc 2025-04-16 06:12:31 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.18

Via RHSA-2025:3775 https://access.redhat.com/errata/RHSA-2025:3775

Comment 14 errata-xmlrpc 2025-04-16 17:46:10 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.17

Via RHSA-2025:3798 https://access.redhat.com/errata/RHSA-2025:3798

Comment 15 errata-xmlrpc 2025-05-08 19:54:39 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.12

Via RHSA-2025:4409 https://access.redhat.com/errata/RHSA-2025:4409

Comment 16 errata-xmlrpc 2025-05-08 19:55:44 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.15

Via RHSA-2025:4422 https://access.redhat.com/errata/RHSA-2025:4422

Comment 17 errata-xmlrpc 2025-05-15 16:34:44 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.13

Via RHSA-2025:4677 https://access.redhat.com/errata/RHSA-2025:4677

Comment 19 errata-xmlrpc 2025-05-21 14:06:43 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.14

Via RHSA-2025:7702 https://access.redhat.com/errata/RHSA-2025:7702