VDB
ALSA-2023%3A4529
ALSA-2023%3A4529
PUBLISHED
The libxml2 library is a development toolbox providing the implementation of various XML standards. Security Fix(es): * libxml2: NULL dereference in xmlSchemaFixupComplexType (CVE-2023-28484) * libxml2: Hashing of empty dict strings isn't deterministic (CVE-2023-29469) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| AlmaLinux:8 | python3-libxml2 | 0, 0 |
| AlmaLinux:8 | libxml2 | 0, 0 |
| AlmaLinux:8 | libxml2-devel | 0, 0 |
Timeline
- Aug 8, 2023 CVE Published
- Feb 4, 2026 CVE Updated
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2023:4529 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-28484 third-party-advisory
- https://access.redhat.com/security/cve/CVE-2023-29469 third-party-advisory
- https://bugzilla.redhat.com/2185984 third-party-advisory
- https://bugzilla.redhat.com/2185994 third-party-advisory
- https://errata.almalinux.org/8/ALSA-2023-4529.html vendor-advisory