CVE-2019-19956
Published: December 24, 2019Last modified: July 22, 2025
Description
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
Severity score breakdown
| Parameter | Value | 
|---|---|
| Base score | 7.5 | 
| Attack Vector | NETWORK | 
| Attack complexity | LOW | 
| Privileges required | NONE | 
| User interaction | NONE | 
| Scope | UNCHANGED | 
| Confidentiality | NONE | 
| Integrity impact | NONE | 
| Availability impact | HIGH | 
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 
Status
| Product | Release | Package | Status | 
|---|---|---|---|
| Alpaquita Linux | 23 LTS | libxml2 | Not affected (2.10.4-r0) | 
| Stream | libxml2 | Not affected (2.11.5-r0) | |
| Hardened Containers | 23 LTS | libxml2 | Not affected (2.10.4-r0) | 
| Stream | libxml2 | Not affected (2.11.5-r0) | 
References
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00047.html
 - http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00005.html
 - https://cert-portal.siemens.com/productcert/pdf/ssa-292794.pdf
 - https://gitlab.gnome.org/GNOME/libxml2/commit/5a02583c7e683896d84878bd90641d8d9b0d0549
 - https://lists.debian.org/debian-lts-announce/2019/12/msg00032.html
 - https://lists.debian.org/debian-lts-announce/2020/09/msg00009.html
 - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5R55ZR52RMBX24TQTWHCIWKJVRV6YAWI/
 - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JDPF3AAVKUAKDYFMFKSIQSVVS3EEFPQH/
 - https://security.netapp.com/advisory/ntap-20200114-0002/
 - https://us-cert.cisa.gov/ics/advisories/icsa-21-103-08
 - https://usn.ubuntu.com/4274-1/
 - https://www.oracle.com/security-alerts/cpujul2020.html