VDB

ALPINE-CVE-2022-29824

ALPINE-CVE-2022-29824 PUBLISHED CVSS 6.5 MEDIUM

In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Alpine:v3.13libxml22.9.9-r3, 2.9.9-r2, 2.9.9-r1
Alpine:v3.18libxml22.9.2-r1, 2.9.2-r0, 2.9.12-r3
Alpine:v3.23libxml22.9.10-r3, 2.9.9-r3, 2.9.12-r0
Alpine:v3.23libxslt0, 0, 0
Alpine:v3.18libxslt0, 0, 0
Alpine:v3.16libxslt0, 0, 0
Alpine:v3.20libxslt0, 0, 0
Alpine:v3.21libxml22.9.10-r2, 2.9.9-r3, 2.9.9-r2
Alpine:v3.22libxml22.7.6-r3, 2.7.7-r1, 2.9.10-r4
Alpine:v3.15libxml22.9.0-r1, 0, 2.7.2-r0
Alpine:v3.21libxslt0, 0, 0
Alpine:v3.17libxml22.7.8-r6, 2.7.8-r7, 2.7.8-r8
Alpine:v3.17libxslt0, 0, 0
Alpine:v3.14libxml22.7.8-r7, 2.9.9-r3, 2.9.9-r2
Alpine:v3.19libxslt0, 0, 0
Alpine:v3.20libxml20, 2.7.2-r0, 2.7.3-r0
Alpine:v3.19libxml22.7.8-r2, 2.9.4-r4, 2.9.5-r0
Alpine:v3.12libxml22.9.9-r3, 2.9.9-r2, 2.9.9-r1
Alpine:v3.16libxml22.9.4-r3, 2.9.4-r4, 2.9.5-r0
Alpine:v3.22libxslt0, 0, 0

Timeline

  • May 3, 2022 CVE Published
  • Dec 3, 2025 CVE Updated
  • Apr 30, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›