CVE-2023-29469
An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string, and any value is possible (not solely the '\0' value).
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Ibm Aix, Linuxmint, Apple Macos, Red Hat
- Xmlsoft libxml2
- < 2.10.4
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 1.0% (60th percentile)
- Weakness
- CWE-415
- NVD status
- Modified
- Published
- 2023-04-24
CVE-2023-29469 at NVD
No indexed exploits for CVE-2023-29469 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-29469 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.