yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2023-28484
Component Overview
Vulnerability Overview
Name
CVE-2023-28484
Source
NVD (
link
)
Debian (
link
)
Description
In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.
CWEs
CWE-476
CWE-476
Published Date
Apr 24, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://gitlab.gnome.org/GNOME/libxml2/-/issues/491
Exploit
https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.10.4
Release Notes
https://lists.debian.org/debian-lts-announce/2023/04/msg00031.html
Mailing List
https://gitlab.gnome.org/GNOME/libxml2/-/issues/491
Exploit
https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.10.4
Release Notes
https://lists.debian.org/debian-lts-announce/2023/04/msg00031.html
Mailing List
Analysis
#
Affected Component
Analysis
libxml2
Patched
Vulnerability Ratings
#
6.5
CVSSv31
6.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libxml2
buildroot
2025.02.x
2.15.3
Not Affected
libxml2
buildroot
master
2.15.3
Not Affected
libxml2
openwrt
master
2.15.3-r1
Not Affected
libxml2
openwrt
openwrt-25.12
2.15.1-r1
Not Affected
libxml2
yocto
master
2.15.3
Not Affected
libxml2
yocto
scarthgap
2.12.10
Not Affected
Resolved with patches
#
libxml2 (yocto:kirkstone)
#
Title
Author
Resolve
1
[CVE-2023-28484] Fix null deref in xmlSchemaFixupComplexType
Nick Wellnhofer <wellnhofer@aevum.de>
CVE-2023-28484