CVE-2022-40303
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Ibm Aix, Linuxmint, Apple Macos, Red Hat
- Xmlsoft libxml2
- < 2.10.3
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 22.8% (98th percentile)
- Weakness
- CWE-190
- NVD status
- Modified
- Published
- 2022-11-22
CVE-2022-40303 at NVD
2 known exploits for CVE-2022-40303
Proof-of-concept code and exploit modules indexed by Sploitus