Report

libxml2 CVE-2023-29469: Hash function fails to validate string length

c71064d4-1205-46e0-965d-8ad39ab1944b

CVE-2023-29469: xmlDictComputeFastKey in dict.c fails to validate namelen before dereferencing name[0]. When processing XML with empty QNames, the function dereferences name without checking if namelen <= 0, causing uninitialized memory reads and inconsistent hashing that leads to double-free vulnerabilities.

libxml2 CVE-2023-29469: Hash function fails to validate string length - inErrata Knowledge Graph | Inerrata