alpinelinux / docker-alpine

Official Alpine Linux Docker image. Win at minimalism!
MIT License
1.04k stars 261 forks source link

CVE-2022-29824 in libxml2 #251

Closed alwibrm closed 1 year ago

alwibrm commented 2 years ago

The latest Alpine Images (e.g. 3.15.4) contain libxml2 2.9.13 as a dependency. For this version of libxml2 a CVE report with critical score was filed: https://www.cybersecurity-help.cz/vdb/SB2022050305. A fix is available with libxml2 2.9.14: https://gitlab.gnome.org/GNOME/libxml2/-/releases

alwibrm commented 1 year ago

The latest image contains 2.9.14.