CVE-2023-29469: Input Validation
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Other sources
Accessibility. This issue was addressed with improved checks.
— Apple
Accounts. A permissions issue was addressed with improved redaction of sensitive information.
— Apple
AMD. A buffer overflow issue was addressed with improved memory handling.
— Apple
An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string, and any value is possible (not solely the '\0' value).
— MITRE
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 16.5 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 16.5 - Upgrade
Upgrade
redhat/libxml2to a version that resolves this vulnerability.Fixed in 2.10.4 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in 2.10.4 - Configuration
Restrict options offered on a locked device.
libxml2 (options handling on locked device) restrict options offered = restricted - Compensating control
Force hardened runtime on the affected binaries at the system level.
- Compensating control
For iOS/macOS Apple environments, ensure the affected binaries have improved entitlements as described in the upstream fix (apply the updated libxml2 package that includes the entitlements changes).
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-32388
- CVE-2023-32400
- CVE-2023-34352
- CVE-2023-32379
- CVE-2023-32411
- CVE-2023-32383
- CVE-2023-32371
- CVE-2023-32386
- CVE-2023-32399
- CVE-2023-28191
- CVE-2023-32360
- CVE-2023-32387
- CVE-2023-32414
- CVE-2023-32417
- CVE-2023-32392
- CVE-2023-32372
- CVE-2023-32384
- CVE-2023-32410
- CVE-2023-32420
- CVE-2023-27930
- CVE-2023-27940
- CVE-2023-32398
- CVE-2023-32413
- CVE-2023-32352
- CVE-2023-29469
- CVE-2023-42869
- CVE-2023-32369
- CVE-2023-32405
- CVE-2023-32428
- CVE-2023-32407
- CVE-2023-42958
- CVE-2023-32368
- CVE-2023-32375
- CVE-2023-32382
- CVE-2023-32380
- CVE-2023-32403
- CVE-2023-32437
- CVE-2023-32355
- CVE-2023-32385
- CVE-2023-32395
- CVE-2023-32390
- CVE-2023-32401
- CVE-2023-32357
- CVE-2023-32363
- CVE-2023-32367
- CVE-2023-32432
- CVE-2023-32397
- CVE-2023-32391
- CVE-2023-32404
- CVE-2023-32394
- CVE-2023-32422
- CVE-2023-32376
- CVE-2023-22809
- CVE-2023-28202
- CVE-2023-32412
- CVE-2023-32408
- CVE-2023-32415
- CVE-2023-32402
- CVE-2023-32423
- CVE-2023-32409
- CVE-2023-28204
- CVE-2023-32373
- CVE-2023-32389
- CVE-2023-32425
- CVE-2023-32419
- CVE-2023-32354
- CVE-2023-32365
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-29469.
What is the severity of CVE-2023-29469?
The severity of CVE-2023-29469 is medium with a CVSS score of 6.5.
What is the affected software?
The affected software is libxml2 versions up to and excluding 2.10.4.
How can I fix CVE-2023-29469?
To fix CVE-2023-29469, you should update to libxml2 version 2.10.4 or above.
Where can I find more information about CVE-2023-29469?
You can find more information about CVE-2023-29469 in the following references: [Link 1](https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.10.4), [Link 2](https://gitlab.gnome.org/GNOME/libxml2/-/commit/09a2dd453007f9c7205274623acdd73747c22d64), [Link 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2185985).