CVE-2023-40128 Information
Oct 28, 2023
cve
Description
In several functions of xmlregexp.c there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Reference
https://android.googlesource.com/platform/external/libxml2/+/1ccf89b87a3969edd56956e2d447f896037c8be7 https://source.android.com/security/bulletin/2023-10-01
Share on: