Debian 10390 Published by

Updated LibXML2 packages are now available for Debian GNU/Linux 11 (Bullseye) LTS, aimed at resolving several vulnerabilities that may result in denial of service or other unintended behaviors:

[SECURITY] [DLA 4064-1] libxml2 security update




[SECURITY] [DLA 4064-1] libxml2 security update


-------------------------------------------------------------------------
Debian LTS Advisory DLA-4064-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Tobias Frost
February 22, 2025 https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package : libxml2
Version : 2.9.10+dfsg-6.7+deb11u6
CVE ID : CVE-2022-49043 CVE-2023-39615 CVE-2023-45322 CVE-2024-25062
CVE-2024-56171 CVE-2025-24928 CVE-2025-27113
Debian Bug : 1051230 1053629 1063234 1094238 1098320 1098321 1098322

Multiple vulnerabilities have been found in libxml2, a library providing
support to read, modify and write XML and HTML files. These
vulnerabilities could potentially lead to denial of servie or other
unintended behaviors.

CVE-2022-49043

xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a
use-after-free.

CVE-2023-39615

libxml2 v2.11.0 was discovered to contain an out-of-bounds read via
the xmlSAX2StartElement() function at /libxml2/SAX2.c. This
vulnerability allows attackers to cause a Denial of Service (DoS)
via supplying a crafted XML file. NOTE: the vendor's position is
that the product does not support the legacy SAX1 interface with
custom callbacks; there is a crash even without crafted input.

CVE-2023-45322

libxml2 through 2.11.5 has a use-after-free that can only occur
after a certain memory allocation fails. This occurs in
xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't
think these issues are critical enough to warrant a CVE ID ...
because an attacker typically can't control when memory allocations
fail."

CVE-2024-25062

An issue was discovered in libxml2 before 2.11.7 and 2.12.x before
2.12.5. When using the XML Reader interface with DTD validation and
XInclude expansion enabled, processing crafted XML documents can
lead to an xmlValidatePopElement use-after-free.

CVE-2024-56171

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free
in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in
xmlschemas.c. To exploit this, a crafted XML document must be
validated against an XML schema with certain identity constraints,
or a crafted XML schema must be used.

CVE-2025-24928

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based
buffer overflow in xmlSnprintfElements in valid.c. To exploit this,
DTD validation must occur for an untrusted document or untrusted
DTD. NOTE: this is similar to CVE-2017-9047.

CVE-2025-27113

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer
dereference in xmlPatMatch in pattern.c.

For Debian 11 bullseye, these problems have been fixed in version
2.9.10+dfsg-6.7+deb11u6.

We recommend that you upgrade your libxml2 packages.

For the detailed security status of libxml2 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libxml2

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS