An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XMLPARSEHUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.
{
"license": "CC-BY-4.0",
"sources": [
{
"published": "2022-11-23T00:15:11.007Z",
"modified": "2025-04-29T05:15:43.693Z",
"id": "CVE-2022-40303",
"imported": "2025-10-28T18:09:09.584Z",
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40303",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2022-40303"
}
]
}