CVE-2023-45322
MEDIUMlibxml2 <= 2.11.5 - Use-After-Free in xmlUnlinkNode
Title source: llmDescription
libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail."
References (4)
Core 4
Core References
Issue Tracking, Patch, Vendor Advisory
https://gitlab.gnome.org/GNOME/libxml2/-/issues/344
Issue Tracking, Patch, Vendor Advisory
https://gitlab.gnome.org/GNOME/libxml2/-/issues/583
Mailing List, Patch, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2023/10/06/5
Scores
CVSS v3
6.5
EPSS
0.0083
EPSS Percentile
52.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-416
Status
published
Products (1)
xmlsoft/libxml2
< 2.11.5
Published
Oct 06, 2023
Tracked Since
Feb 18, 2026