CVE-2022-2309 is a NULL Pointer Dereference vulnerability in lxml when used with libxml2 versions 2.9.10 through 2.9.14, allowing attackers to trigger a denial of service via crafted input data processed by the iterwalk or canonicalize functions. With a CVSS score of 7.5 (High), this vulnerability requires no user interaction and can be exploited remotely, leading to an application crash. While the specific vulnerable code sequence is not expected to be widespread, legitimate use cases exist, particularly in XML conversion scenarios. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.9.1CPE matchmatch criteria | cpe:2.3:a:lxml:lxml:*:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
August 2023 Third Party Package Updates in Splunk Enterprise
Aug 30, 2023NULL Pointer Dereference in lxml/lxml
Jul 12, 2022lxml NULL Pointer Dereference allows attackers to cause a denial of service
Jul 6, 2022lxml: NULL Pointer Dereference in lxml
Jul 5, 2022