CVE-2023-45322

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
06/10/2023
Last modified:
03/11/2025

Description

libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* 2.11.5 (including)