CVE-2021-3518: Use After Free
ActionKit. An input validation issue was addressed with improved input validation.
Other sources
AMD Kernel. A memory corruption issue was addressed with improved input validation.
— Apple
An use-after-free was found in libxml2 in xmlXIncludeDoProcess() in xinclude.c when processing crafted files.
Reference: https://gitlab.gnome.org/GNOME/libxml2/-/issues/237
Upstream patch: https://gitlab.gnome.org/GNOME/libxml2/-/commit/1098c30a040e72a4654968547f415be4e4c40fe7
— Red Hat
Analytics. A logic issue was addressed with improved restrictions.
— Apple
Analytics. This issue was addressed with a new entitlement.
— Apple
App Store. A permissions issue was addressed with improved validation.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rubygems/nokogirito a version that resolves this vulnerability.Fixed in 1.11.4 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-91.el8 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.78.0-3.el8 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-80.el8 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-41.el8 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1g-11.el8 - Upgrade
Upgrade
redhat/jbcs-httpd24-openssl-chilto a version that resolves this vulnerability.Fixed in 0:1.0.0-11.el8 - Upgrade
Upgrade
redhat/jbcs-httpd24-openssl-pkcs11to a version that resolves this vulnerability.Fixed in 0:0.4.10-26.el8 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-91.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.78.0-3.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-80.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-41.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1g-11.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-openssl-chilto a version that resolves this vulnerability.Fixed in 0:1.0.0-11.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-openssl-pkcs11to a version that resolves this vulnerability.Fixed in 0:0.4.10-26.jbcs.el7 - Upgrade
Upgrade
redhat/libxml2to a version that resolves this vulnerability.Fixed in 0:2.9.7-9.el8_4.2 - Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 11.5 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 14.7 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 7.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.6 - Upgrade
Upgrade
redhat/libxml2to a version that resolves this vulnerability.Fixed in 2.9.11 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in 2.9.11 - Compensating control
When processing untrusted files, ensure the application linked with libxml2 does not process attacker-supplied crafted files (e.g., validate/sandbox file handling before calling into libxml2), since a crafted file could trigger a use-after-free in xmlXIncludeDoProcess() (xinclude.c) leading to arbitrary code execution.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-30805
- CVE-2021-30871
- CVE-2021-30790
- CVE-2021-31006
- CVE-2021-30781
- CVE-2021-30748
- CVE-2021-30775
- CVE-2021-30776
- CVE-2021-30786
- CVE-2021-30772
- CVE-2021-30783
- CVE-2021-30777
- CVE-2021-30789
- CVE-2021-30774
- CVE-2021-30780
- CVE-2021-30768
- CVE-2021-30817
- CVE-2021-30804
- CVE-2021-30760
- CVE-2021-30788
- CVE-2021-30759
- CVE-2021-30803
- CVE-2021-30779
- CVE-2021-30785
- CVE-2021-30787
- CVE-2021-30766
- CVE-2021-30765
- CVE-2021-30784
- CVE-2021-30793
- CVE-2021-30778
- CVE-2021-30677
- CVE-2021-3518
- CVE-2021-30796
- CVE-2021-30792
- CVE-2021-30791
- CVE-2021-1821
- CVE-2021-30782
- CVE-2021-31004
- CVE-2021-30798
- CVE-2021-30758
- CVE-2021-30795
- CVE-2021-30797
- CVE-2021-30799
- CVE-2021-30773
- CVE-2021-30802
- CVE-2021-30769
- CVE-2021-30770
- CVE-2021-30763
- CVE-2018-25010
- CVE-2018-25011
- CVE-2018-25014
- CVE-2020-36328
- CVE-2020-36329
- CVE-2020-36330
- CVE-2020-36331
- CVE-2021-30800
Frequently Asked Questions
What is CVE-2021-3518?
CVE-2021-3518 is a vulnerability in libxml2 before version 2.9.11 that allows an attacker to trigger a use-after-free by submitting a crafted file to an application linked with libxml2.
What is the impact of CVE-2021-3518?
The greatest impact of CVE-2021-3518 is to the confidentiality, integrity, and availability of the affected system.
Which software versions are affected by CVE-2021-3518?
CVE-2021-3518 affects Apple watchOS up to version 7.6, Apple tvOS up to version 14.7, Apple macOS Big Sur up to version 11.5, and various packages from Red Hat.
How can I fix CVE-2021-3518?
To fix CVE-2021-3518, update to libxml2 version 2.9.11 or later for Apple products, and apply the relevant patches or updates for Red Hat packages.
Where can I find more information about CVE-2021-3518?
You can find more information about CVE-2021-3518 on the Apple support website at the provided reference links.