Description
A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
Affected products
- ibm / aix7.2.5 – 7.2.5.12
- ibm / aix7.3.4 – 7.3.4
- ibm / vios4.1.0 – 4.1.1.30
- ibm / vios4.1.2.0 – 4.1.2.0
- RedHat / enterprise_linux10.0 – 10.0
- RedHat / enterprise_linux8.0 – 8.0
- RedHat / enterprise_linux6.0 – 6.0
- RedHat / enterprise_linux7.0 – 7.0
- RedHat / enterprise_linux9.0 – 9.0
- RedHat / hardened_images
- RedHat / jboss_core_services
- RedHat / openshift_container_platform4.0 – 4.0
- xmlsoft / libxml22.15.2
Updated 8m ago · 8 sources