{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Low"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "use-after-free in xmlUnlinkNode() in tree.c",
    "tracking": {
      "current_release_date": "2026-07-27T10:01:42+00:00",
      "generator": {
        "date": "2026-07-27T10:01:42+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.1.0"
        }
      },
      "id": "CVE-2023-45322",
      "initial_release_date": "2023-08-23T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-07-27T10:01:42+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 6-els",
            "product": {
              "name": "Red Hat Enterprise Linux 6-els",
              "product_id": "rhel-6-els.els",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:rhel_els:6"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 7.9.z",
            "product": {
              "name": "Red Hat Enterprise Linux 7.9.z",
              "product_id": "rhel-7.els",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:rhel_els:7"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 8.10.z",
            "product": {
              "name": "Red Hat Enterprise Linux 8.10.z",
              "product_id": "rhel-8",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:8"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 9.9",
            "product": {
              "name": "Red Hat Enterprise Linux 9.9",
              "product_id": "rhel-9",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "libxml2",
            "product": {
              "name": "libxml2",
              "product_id": "libxml2",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/libxml2"
              }
            }
          },
          {
            "category": "product_version",
            "name": "libxml2-debuginfo",
            "product": {
              "name": "libxml2-debuginfo",
              "product_id": "libxml2-debuginfo",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/libxml2-debuginfo"
              }
            }
          },
          {
            "category": "product_version",
            "name": "libxml2-devel",
            "product": {
              "name": "libxml2-devel",
              "product_id": "libxml2-devel",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/libxml2-devel"
              }
            }
          },
          {
            "category": "product_version",
            "name": "libxml2-python",
            "product": {
              "name": "libxml2-python",
              "product_id": "libxml2-python",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/libxml2-python"
              }
            }
          },
          {
            "category": "product_version",
            "name": "libxml2-static",
            "product": {
              "name": "libxml2-static",
              "product_id": "libxml2-static",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/libxml2-static"
              }
            }
          },
          {
            "category": "product_version",
            "name": "libxml2",
            "product": {
              "name": "libxml2",
              "product_id": "libxml2.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/libxml2?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libxml2 as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:libxml2"
        },
        "product_reference": "libxml2",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libxml2 as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.els:libxml2"
        },
        "product_reference": "libxml2",
        "relates_to_product_reference": "rhel-7.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libxml2-debuginfo as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:libxml2-debuginfo"
        },
        "product_reference": "libxml2-debuginfo",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libxml2-devel as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:libxml2-devel"
        },
        "product_reference": "libxml2-devel",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libxml2-devel as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.els:libxml2-devel"
        },
        "product_reference": "libxml2-devel",
        "relates_to_product_reference": "rhel-7.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libxml2-devel as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:libxml2-devel"
        },
        "product_reference": "libxml2-devel",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libxml2-devel as a component of Red Hat Enterprise Linux 9.9",
          "product_id": "rhel-9:libxml2-devel"
        },
        "product_reference": "libxml2-devel",
        "relates_to_product_reference": "rhel-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libxml2-python as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.els:libxml2-python"
        },
        "product_reference": "libxml2-python",
        "relates_to_product_reference": "rhel-7.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libxml2-python as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:libxml2-python"
        },
        "product_reference": "libxml2-python",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libxml2-static as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.els:libxml2-static"
        },
        "product_reference": "libxml2-static",
        "relates_to_product_reference": "rhel-7.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libxml2-static as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:libxml2-static"
        },
        "product_reference": "libxml2-static",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libxml2.src as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:libxml2.src"
        },
        "product_reference": "libxml2.src",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libxml2.src as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.els:libxml2.src"
        },
        "product_reference": "libxml2.src",
        "relates_to_product_reference": "rhel-7.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libxml2.src as a component of Red Hat Enterprise Linux 9.9",
          "product_id": "rhel-9:libxml2.src"
        },
        "product_reference": "libxml2.src",
        "relates_to_product_reference": "rhel-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libxml2.src as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:libxml2.src"
        },
        "product_reference": "libxml2.src",
        "relates_to_product_reference": "rhel-6-els.els"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-45322",
      "cwe": {
        "id": "CWE-416",
        "name": "Use After Free"
      },
      "discovery_date": "2023-10-06T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "rhel-6-els.els:libxml2-debuginfo",
            "rhel-6-els.els:libxml2-devel",
            "rhel-6-els.els:libxml2-static",
            "rhel-7.els:libxml2-devel",
            "rhel-7.els:libxml2-static",
            "rhel-8:libxml2-devel",
            "rhel-9:libxml2-devel"
          ]
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "The libxml2 project does not consider this issue to be a vulnerability because it can only be triggered in an out-of-memory condition or when the --maxmem command line option of the xmllint program is used to limit the number of memory allocation done by the parser. This is intended behavior and it's used to detect similar issues.\n\nRed Hat Product Security agrees with that decision. However, Red Hat will try to address this issue in affected products.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "A flaw was found in libxml2. In an out-of-memory condition or when limiting the memory allocation, processing a XML document using the HTML parser may result in a use-after-free vulnerability.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "rhel-6-els.els:libxml2",
          "rhel-6-els.els:libxml2-python",
          "rhel-6-els.els:libxml2.src",
          "rhel-7.els:libxml2",
          "rhel-7.els:libxml2-python",
          "rhel-7.els:libxml2.src",
          "rhel-8:libxml2.src",
          "rhel-9:libxml2.src"
        ],
        "known_not_affected": [
          "rhel-6-els.els:libxml2-debuginfo",
          "rhel-6-els.els:libxml2-devel",
          "rhel-6-els.els:libxml2-static",
          "rhel-7.els:libxml2-devel",
          "rhel-7.els:libxml2-static",
          "rhel-8:libxml2-devel",
          "rhel-9:libxml2-devel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2023-45322"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45322"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45322"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Out of support scope",
          "product_ids": [
            "rhel-6-els.els:libxml2",
            "rhel-6-els.els:libxml2-python",
            "rhel-6-els.els:libxml2.src"
          ]
        },
        {
          "category": "no_fix_planned",
          "details": "Will not fix",
          "product_ids": [
            "rhel-7.els:libxml2",
            "rhel-7.els:libxml2-python",
            "rhel-7.els:libxml2.src",
            "rhel-8:libxml2.src",
            "rhel-9:libxml2.src"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM"
          },
          "products": [
            "rhel-6-els.els:libxml2",
            "rhel-6-els.els:libxml2-debuginfo",
            "rhel-6-els.els:libxml2-devel",
            "rhel-6-els.els:libxml2-python",
            "rhel-6-els.els:libxml2-static",
            "rhel-6-els.els:libxml2.src",
            "rhel-7.els:libxml2",
            "rhel-7.els:libxml2-devel",
            "rhel-7.els:libxml2-python",
            "rhel-7.els:libxml2-static",
            "rhel-7.els:libxml2.src",
            "rhel-8:libxml2-devel",
            "rhel-8:libxml2.src",
            "rhel-9:libxml2-devel",
            "rhel-9:libxml2.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low",
          "product_ids": [
            "rhel-6-els.els:libxml2",
            "rhel-6-els.els:libxml2-debuginfo",
            "rhel-6-els.els:libxml2-devel",
            "rhel-6-els.els:libxml2-python",
            "rhel-6-els.els:libxml2-static",
            "rhel-6-els.els:libxml2.src",
            "rhel-7.els:libxml2",
            "rhel-7.els:libxml2-devel",
            "rhel-7.els:libxml2-python",
            "rhel-7.els:libxml2-static",
            "rhel-7.els:libxml2.src",
            "rhel-8:libxml2-devel",
            "rhel-8:libxml2.src",
            "rhel-9:libxml2-devel",
            "rhel-9:libxml2.src"
          ]
        }
      ],
      "title": "use-after-free in xmlUnlinkNode() in tree.c"
    }
  ]
}