CVE-2022-40303 is a high-severity vulnerability in libxml2 (versions prior to 2.10.3) that affects products from Apple, NetApp, and xmlsoft. It allows an unauthenticated attacker to trigger a denial-of-service (segmentation fault) by providing a specially crafted, multi-gigabyte XML document when the XML_PARSE_HUGE option is enabled. This is due to integer overflows leading to an attempt to access an array at a negative offset. While there are no known public exploits or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion and media coverage, with specific mentions of macOS Monterey remaining vulnerable.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.10.3CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:clustered_data_ontap_antivirus_connector:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:netapp_manageability_sdk:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
June Third Party Package Updates in Splunk Cloud
Jun 1, 2023An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset typically leading to a segmentation fault.
Nov 8, 2022libxml2: integer overflows with XML_PARSE_HUGE
Oct 14, 2022libxml2 vulnerabilities
libxml2 vulnerabilities (CVE-2022-40303, CVE-2022-40304)
libxml2 vulnerabilities
libxml2 Vulnerabilities
libxml2 vulnerabilities resolved
libxml2 vulnerabilities
libxml2 vulnerabilities