yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-40304
Component Overview
Vulnerability Overview
Name
CVE-2022-40304
Source
NVD (
link
)
Debian (
link
)
Description
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
CWEs
CWE-415
CWE-415
Published Date
Nov 23, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://seclists.org/fulldisclosure/2022/Dec/21
Mailing List
http://seclists.org/fulldisclosure/2022/Dec/24
Mailing List
http://seclists.org/fulldisclosure/2022/Dec/25
Mailing List
http://seclists.org/fulldisclosure/2022/Dec/26
Mailing List
https://gitlab.gnome.org/GNOME/libxml2/-/commit/1b41ec4e9433b05bb0376be4725804c54ef1d80b
Patch
https://gitlab.gnome.org/GNOME/libxml2/-/tags
Release Notes
https://gitlab.gnome.org/GNOME/libxml2/-/tags/v2.10.3
Patch
https://security.netapp.com/advisory/ntap-20221209-0003/
Third Party Advisory
https://support.apple.com/kb/HT213531
Third Party Advisory
https://support.apple.com/kb/HT213533
Third Party Advisory
https://support.apple.com/kb/HT213534
Third Party Advisory
https://support.apple.com/kb/HT213535
Third Party Advisory
https://support.apple.com/kb/HT213536
Third Party Advisory
http://seclists.org/fulldisclosure/2022/Dec/21
Mailing List
http://seclists.org/fulldisclosure/2022/Dec/24
Mailing List
http://seclists.org/fulldisclosure/2022/Dec/25
Mailing List
http://seclists.org/fulldisclosure/2022/Dec/26
Mailing List
https://gitlab.gnome.org/GNOME/libxml2/-/commit/1b41ec4e9433b05bb0376be4725804c54ef1d80b
Patch
https://gitlab.gnome.org/GNOME/libxml2/-/tags
Release Notes
https://gitlab.gnome.org/GNOME/libxml2/-/tags/v2.10.3
Patch
https://security.netapp.com/advisory/ntap-20221209-0003/
Third Party Advisory
https://support.apple.com/kb/HT213531
Third Party Advisory
https://support.apple.com/kb/HT213533
Third Party Advisory
https://support.apple.com/kb/HT213534
Third Party Advisory
https://support.apple.com/kb/HT213535
Third Party Advisory
https://support.apple.com/kb/HT213536
Third Party Advisory
Analysis
#
Affected Component
Analysis
libxml2
Patched
Vulnerability Ratings
#
7.8
CVSSv31
7.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libxml2
buildroot
2025.02.x
2.15.3
Not Affected
libxml2
buildroot
master
2.15.3
Not Affected
libxml2
openwrt
master
2.15.3-r1
Not Affected
libxml2
openwrt
openwrt-25.12
2.15.1-r1
Not Affected
libxml2
yocto
master
2.15.3
Not Affected
libxml2
yocto
scarthgap
2.12.10
Not Affected
Resolved with patches
#
libxml2 (yocto:kirkstone)
#
Title
Author
Resolve
1
CVE-2022-40304
Nick Wellnhofer <wellnhofer@aevum.de>
CVE-2022-40304