CVE Identifier: CVE-2023-45322 Vulnerability Type: Use-after-free Affected Software: libxml2 versions 2 through 2.11.5 Description: The vulnerability occurs in the function in when a certain memory allocation fails. Vendor Position: The vendor does not consider these issues critical enough for a CVE ID, as attackers typically cannot control when memory allocations fail. Reproducer: Attached to the upstream bug report at https://gitlab.gnome.org/GNOME/libxml2/-/issues/583. Run it via . Fix: Available in the git master branch but not yet in any release. https://gitlab.gnome.org/GNOME/libxml2/-/commit/d39f78069dff496ec865c73aa44d7110e429bce9