Mageia 2023-0298: libxml2 security update
Summary
libxml2 through 2.11.5 has a use-after-free that can only occur after a
certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c.
(CVE-2023-45322)
References
- https://bugs.mageia.org/show_bug.cgi?id=32364
- https://www.openwall.com/lists/oss-security/2023/10/06/5
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45322
Resolution
MGASA-2023-0298 - Updated libxml2 packages fix a security vulnerability
SRPMS
- 9/core/libxml2-2.10.4-1.2.mga9
- 8/core/libxml2-2.9.10-7.9.mga8