]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
libxml2: ignore disputed CVE-2023-45322
authorRoss Burton <ross.burton@arm.com>
Mon, 23 Oct 2023 17:38:19 +0000 (18:38 +0100)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Thu, 26 Oct 2023 14:28:23 +0000 (15:28 +0100)
commitb93dd888b861aa6df97cd78b70fa9f757cfcdf61
tree8779420129297421f1ed06a2f18e8963f576e8ab
parent3331f53c0be2575784a042bb2401eeba4f2a5a3e
libxml2: ignore disputed CVE-2023-45322

This CVE is a use-after-free which theoretically can be an exploit
vector, but this UAF only occurs when malloc() fails.  As it's
unlikely that the user can orchestrate malloc() failures at just the
place to break on _this_ malloc and not others it is disputed that this
is actually a security issue.

The underlying bug has been fixed, and will be incorporated into the
next release.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-core/libxml/libxml2_2.11.5.bb