CVE-2022-23308
published 2022-02-26CVE-2022-23308: valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
6.01%
92.5th percentile
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.5_and_ipados | — | — |
| apple | ipados | < 15.5 | 15.5 |
| apple | iphone_os | < 15.5 | 15.5 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.15.0 < 10.15.7 | 10.15.7 |
| apple | macos | >= 11.6.0 < 11.6.6 | 11.6.6 |
| apple | macos | >= 12.0 < 12.4 | 12.4 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | security_update_2022-004_catalina | — | — |
| apple | tvos | < 15.5 | 15.5 |
| apple | tvos | — | — |
| apple | watchos | < 8.6 | 8.6 |
| apple | watchos | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.9.13+dfsg-1 (bookworm) | libxml2 2.9.13+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| chrome_chrome | — | — | |
| msrc | cbl2_libxml2_2.9.13-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_libxml2_2.9.13-1_on_cbl_mariner_1.0 | — | — |
| nokogiri | nokogiri | >= 0 < 1.13.2 | 1.13.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
ghsa8.8HIGH
osv8.8HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
libxml2 up to 2.9.12 valid.c ID/IDREF use after free (EUVD-2022-28391 / Nessus ID 236689)
vuldb·2026-04-30·CVSS 7.5
CVE-2022-23308 [HIGH] libxml2 up to 2.9.12 valid.c ID/IDREF use after free (EUVD-2022-28391 / Nessus ID 236689)
A vulnerability was found in libxml2 up to 2.9.12 and classified as critical. The impacted element is an unknown function of the file valid.c. Such manipulation of the argument ID/IDREF leads to use after free.
This vulnerability is traded as CVE-2022-23308. Access to the local network is required for this attack to succeed. There is no exploit available.
It is suggested to upgrade the affected component.
VulDB
Apple watchOS up to 8.5.1 libxml2 use after free (HT213253 / EUVD-2022-28391)
vuldb·2026-04-30·CVSS 7.5
CVE-2022-23308 [HIGH] Apple watchOS up to 8.5.1 libxml2 use after free (HT213253 / EUVD-2022-28391)
A vulnerability labeled as critical has been found in Apple watchOS up to 8.5.1. Impacted is an unknown function of the component libxml2. Such manipulation leads to use after free.
This vulnerability is traded as CVE-2022-23308. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
VulDB
Apple iOS/iPadOS up to 15.4.1 libxml2 use after free (HT213258 / EUVD-2022-28391)
vuldb·2026-04-30·CVSS 7.5
CVE-2022-23308 [HIGH] Apple iOS/iPadOS up to 15.4.1 libxml2 use after free (HT213258 / EUVD-2022-28391)
A vulnerability, which was classified as critical, has been found in Apple iOS and iPadOS up to 15.4.1. Affected by this issue is some unknown functionality of the component libxml2. This manipulation causes use after free.
This vulnerability is tracked as CVE-2022-23308. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
OSV
libxml2 vulnerabilities
osv·2022-05-16·CVSS 7.5
CVE-2022-23308 [HIGH] libxml2 vulnerabilities
libxml2 vulnerabilities
Shinji Sato discovered that libxml2 incorrectly handled certain XML files.
An attacker could possibly use this issue to cause a crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 14.04 ESM, and Ubuntu 16.04 ESM. (CVE-2022-23308)
It was discovered that libxml2 incorrectly handled certain XML files.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. (CVE-2022-29824)
GHSA
GHSA-8v47-xfh7-92fh: valid
ghsa_unreviewed·2022-02-27
CVE-2022-23308 [HIGH] CWE-416 GHSA-8v47-xfh7-92fh: valid
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
OSV
CVE-2022-23308: valid
osv·2022-02-26·CVSS 7.5
CVE-2022-23308 [HIGH] CVE-2022-23308: valid
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
OSV
Vulnerable dependencies in Nokogiri
osv·2022-02-25·CVSS 8.8
CVE-2021-30560 [HIGH] Vulnerable dependencies in Nokogiri
Vulnerable dependencies in Nokogiri
### Summary
Nokogiri [v1.13.2](https://github.com/sparklemotion/nokogiri/releases/tag/v1.13.2) upgrades two of its packaged dependencies:
- vendored libxml2 from v2.9.12 to [v2.9.13](https://download.gnome.org/sources/libxml2/2.9/libxml2-2.9.13.news)
- vendored libxslt from v1.1.34 to [v1.1.35](https://download.gnome.org/sources/libxslt/1.1/libxslt-1.1.35.news)
Those library versions address the following upstream CVEs:
- libxslt: [CVE-2021-30560](https://nvd.nist.gov/vuln/detail/CVE-2021-30560) (CVSS 8.8, High severity)
- libxml2: [CVE-2022-23308](https://nvd.nist.gov/vuln/detail/CVE-2022-23308) (Unspecified severity, see more information below)
Those library versions also address numerous other issues including performance improvements, regressio
GHSA
Vulnerable dependencies in Nokogiri
ghsa·2022-02-25·CVSS 8.8
CVE-2021-30560 [HIGH] CWE-416 Vulnerable dependencies in Nokogiri
Vulnerable dependencies in Nokogiri
### Summary
Nokogiri [v1.13.2](https://github.com/sparklemotion/nokogiri/releases/tag/v1.13.2) upgrades two of its packaged dependencies:
- vendored libxml2 from v2.9.12 to [v2.9.13](https://download.gnome.org/sources/libxml2/2.9/libxml2-2.9.13.news)
- vendored libxslt from v1.1.34 to [v1.1.35](https://download.gnome.org/sources/libxslt/1.1/libxslt-1.1.35.news)
Those library versions address the following upstream CVEs:
- libxslt: [CVE-2021-30560](https://nvd.nist.gov/vuln/detail/CVE-2021-30560) (CVSS 8.8, High severity)
- libxml2: [CVE-2022-23308](https://nvd.nist.gov/vuln/detail/CVE-2022-23308) (Unspecified severity, see more information below)
Those library versions also address numerous other issues including performance improvements, regressio
CISA ICS
Siemens SINAMICS Medium Voltage Products
cisa_ics·2023-06-15·CVSS 7.5
[HIGH] Siemens SINAMICS Medium Voltage Products
ICS Advisory
##
Siemens SINAMICS Medium Voltage Products
Release DateJune 15, 2023
Alert CodeICSA-23-166-12
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: SINAMICS MV (medium voltage) products
- Vulnerabilities: Out-of-bounds Write, Out-of-bounds Read, Use After Free, Improper Authentication, OS Command Injection, Improper Certificate Validation, Improper Res
CISA ICS
Siemens SCALANCE, RUGGEDCOM Third-Party
cisa_ics·2023-03-16
Siemens SCALANCE, RUGGEDCOM Third-Party
ICS Advisory
##
Siemens SCALANCE, RUGGEDCOM Third-Party
Release DateMarch 16, 2023
Alert CodeICSA-23-075-01
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: Busybox Applet affecting SCALANCE and RUGGEDCOM products
- Vulnerabilities: Out-of-bounds Write, Exposure of Sensitive Information to an Unauthorized Actor, Improper Locking, Improper Input Validation, NULL Pointer Deref
Oracle
Oracle Oracle Communications Risk Matrix: BSF (libxml2) — CVE-2022-23308
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2022-23308 [HIGH] Oracle Oracle Communications Risk Matrix: BSF (libxml2) — CVE-2022-23308
Oracle Oracle Communications Risk Matrix: BSF (libxml2) vulnerability
CVE: CVE-2022-23308
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2022-1859
vendor_chrome·2022-05-31·CVSS 9.8
CVE-2022-1859 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2022-1859
Long Term Support Channel Update for ChromeOS
CVE-2022-1859: Use after free in Performance Manager. 1297283 High CVE-2022-1636: Use after free in Performance APIs 1278608 High CVE-2021-43527 [internally reported] 1304660 High CVE-2022-23308 CrOS: Vulnerability reported in dev-libs/libxml2 1315563 Medium CVE-2022-1867: Insufficient validation of untrusted input in Data Transfer
Severity: high
Apple
CVE-2022-23308: tvOS 15.5
vendor_apple·2022-05-16·CVSS 7.5
CVE-2022-23308 [HIGH] CVE-2022-23308: tvOS 15.5
Apple Security Update: About the security content of tvOS 15.5
Product: tvOS
Version: 15.5
CVE: CVE-2022-23308
Component: CVE-2022-23308
Apple
CVE-2022-23308: Security Update 2022-004 Catalina
vendor_apple·2022-05-16·CVSS 7.5
CVE-2022-23308 [HIGH] CVE-2022-23308: Security Update 2022-004 Catalina
Apple Security Update: About the security content of Security Update 2022-004 Catalina
Product: Security Update 2022-004 Catalina
CVE: CVE-2022-23308
Component: CVE-2022-23308
Apple
CVE-2022-23308: iOS 15.5 and iPadOS 15.5
vendor_apple·2022-05-16·CVSS 7.5
CVE-2022-23308 [HIGH] CVE-2022-23308: iOS 15.5 and iPadOS 15.5
Apple Security Update: About the security content of iOS 15.5 and iPadOS 15.5
Product: iOS 15.5 and iPadOS
Version: 15.5
CVE: CVE-2022-23308
Component: CVE-2022-23308
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2022-05-16·CVSS 7.5
CVE-2022-29824 [HIGH] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: Several security issues were fixed in libxml2.
Shinji Sato discovered that libxml2 incorrectly handled certain XML files.
An attacker could possibly use this issue to cause a crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 14.04 ESM, and Ubuntu 16.04 ESM. (CVE-2022-23308)
It was discovered that libxml2 incorrectly handled certain XML files.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. (CVE-2022-29824)
Instructions: In general, a standard system update will make all the necessary changes.
Apple
CVE-2022-23308: watchOS 8.6
vendor_apple·2022-05-16·CVSS 7.5
CVE-2022-23308 [HIGH] CVE-2022-23308: watchOS 8.6
Apple Security Update: About the security content of watchOS 8.6
Product: watchOS
Version: 8.6
CVE: CVE-2022-23308
Component: CVE-2022-23308
Apple
CVE-2022-23308: macOS Big Sur 11.6.6
vendor_apple·2022-05-16·CVSS 7.5
CVE-2022-23308 [HIGH] CVE-2022-23308: macOS Big Sur 11.6.6
Apple Security Update: About the security content of macOS Big Sur 11.6.6
Product: macOS Big Sur
Version: 11.6.6
CVE: CVE-2022-23308
Component: CVE-2022-23308
Apple
CVE-2022-23308: macOS Monterey 12.4
vendor_apple·2022-05-16·CVSS 7.5
CVE-2022-23308 [HIGH] CVE-2022-23308: macOS Monterey 12.4
Apple Security Update: About the security content of macOS Monterey 12.4
Product: macOS Monterey
Version: 12.4
CVE: CVE-2022-23308
Component: CVE-2022-23308
Ubuntu
libxml2 vulnerability
vendor_ubuntu·2022-03-14
CVE-2022-23308 libxml2 vulnerability
Title: libxml2 vulnerability
Summary: libxml2 could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that libxml2 incorrectly handled certain XML files. An
attacker could use this issue to cause libxml2 to crash, resulting in a
denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libxml2: Use-after-free of ID and IDREF attributes
vendor_redhat·2022-02-20·CVSS 7.5
CVE-2022-23308 [HIGH] CWE-416 libxml2: Use-after-free of ID and IDREF attributes
libxml2: Use-after-free of ID and IDREF attributes
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
A flaw was found in libxml2. A call to the xmlGetID function can return a pointer already freed when parsing an XML document with the XML_PARSE_DTDVALID option and without the XML_PARSE_NOENT option, resulting in a use-after-free issue.
Statement: The security impact of xmlGetID() returning a pointer to freed memory depends on the application and will mostly result in a denial of service (DoS). The typical use case of calling xmlGetID() on an unmodified document is not affected, therefore this issue was rated with a moderate severity.
Package: libxml2 (Red Hat Enterprise Linux 6) - Out of support scope
Package: libxml2 (Red Hat Enterprise Linux 7) - Out
Microsoft
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
vendor_msrc·2022-02-08·CVSS 7.5
CVE-2022-23308 [HIGH] CWE-416 valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Debian
CVE-2022-23308: libxml2 - valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes...
vendor_debian·2022·CVSS 7.5
CVE-2022-23308 [HIGH] CVE-2022-23308: libxml2 - valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes...
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
Scope: local
bookworm: resolved (fixed in 2.9.13+dfsg-1)
bullseye: resolved (fixed in 2.9.10+dfsg-6.7+deb11u1)
forky: resolved (fixed in 2.9.13+dfsg-1)
sid: resolved (fixed in 2.9.13+dfsg-1)
trixie: resolved (fixed in 2.9.13+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2022/May/33http://seclists.org/fulldisclosure/2022/May/34http://seclists.org/fulldisclosure/2022/May/35http://seclists.org/fulldisclosure/2022/May/36http://seclists.org/fulldisclosure/2022/May/37http://seclists.org/fulldisclosure/2022/May/38https://github.com/GNOME/libxml2/commit/652dd12a858989b14eed4e84e453059cd3ba340ehttps://gitlab.gnome.org/GNOME/libxml2/-/blob/v2.9.13/NEWShttps://lists.debian.org/debian-lts-announce/2022/04/msg00004.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LA3MWWAYZADWJ5F6JOUBX65UZAMQB7RF/https://security.gentoo.org/glsa/202210-03https://security.netapp.com/advisory/ntap-20220331-0008/https://support.apple.com/kb/HT213253https://support.apple.com/kb/HT213254https://support.apple.com/kb/HT213255https://support.apple.com/kb/HT213256https://support.apple.com/kb/HT213257https://support.apple.com/kb/HT213258https://www.oracle.com/security-alerts/cpujul2022.htmlhttp://seclists.org/fulldisclosure/2022/May/33http://seclists.org/fulldisclosure/2022/May/34http://seclists.org/fulldisclosure/2022/May/35http://seclists.org/fulldisclosure/2022/May/36http://seclists.org/fulldisclosure/2022/May/37http://seclists.org/fulldisclosure/2022/May/38https://github.com/GNOME/libxml2/commit/652dd12a858989b14eed4e84e453059cd3ba340ehttps://gitlab.gnome.org/GNOME/libxml2/-/blob/v2.9.13/NEWShttps://lists.debian.org/debian-lts-announce/2022/04/msg00004.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LA3MWWAYZADWJ5F6JOUBX65UZAMQB7RF/https://security.gentoo.org/glsa/202210-03https://security.netapp.com/advisory/ntap-20220331-0008/https://support.apple.com/kb/HT213253https://support.apple.com/kb/HT213254https://support.apple.com/kb/HT213255https://support.apple.com/kb/HT213256https://support.apple.com/kb/HT213257https://support.apple.com/kb/HT213258https://www.oracle.com/security-alerts/cpujul2022.html
2022-02-26
Published