Description
A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
Affected products
- ibm / aix7.2.5 – 7.2.5.12
- ibm / aix7.3.4 – 7.3.4
- ibm / vios4.1.2.0 – 4.1.2.0
- ibm / vios4.1.0 – 4.1.1.30
- RedHat / enterprise_linux7.0 – 7.0
- RedHat / enterprise_linux8.0 – 8.0
- RedHat / enterprise_linux9.0 – 9.0
- RedHat / enterprise_linux10.0 – 10.0
- RedHat / enterprise_linux6.0 – 6.0
- RedHat / hardened_images
- RedHat / jboss_core_services
- RedHat / openshift_container_platform4.0 – 4.0
- xmlsoft / libxml22.15.2
Updated 8m ago · 8 sources