xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs. Upstream Fix: https://gitlab.gnome.org/GNOME/libxml2/commit/5a02583c7e683896d84878bd90641d8d9b0d0549
Created libxml2 tracking bugs for this issue: Affects: fedora-30 [bug 1788857] Created mingw-libxml2 tracking bugs for this issue: Affects: epel-7 [bug 1788859] Affects: fedora-all [bug 1788858]
Already fixed where libxml2-2.9.10 is present [*]: Rawhide/F32: https://bodhi.fedoraproject.org/updates/FEDORA-2019-44d48a72e5 F31: https://bodhi.fedoraproject.org/updates/FEDORA-2019-92097b71ff Do we want/need to address this in F30 as well? see: https://gitlab.gnome.org/GNOME/libxml2/commits/41a34e1f4ffae2ce401600dbb5fe43f8fe402641
Upstream bug: https://gitlab.gnome.org/GNOME/libxml2/issues/82
This issue has been addressed in the following products: JBoss Core Services on RHEL 6 JBoss Core Services on RHEL 7 Via RHSA-2020:2644 https://access.redhat.com/errata/RHSA-2020:2644
This issue has been addressed in the following products: Red Hat JBoss Core Services Via RHSA-2020:2646 https://access.redhat.com/errata/RHSA-2020:2646
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-19956
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:3996 https://access.redhat.com/errata/RHSA-2020:3996
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:4479 https://access.redhat.com/errata/RHSA-2020:4479
(In reply to errata-xmlrpc from comment #10) > This issue has been addressed in the following products: > > Red Hat Enterprise Linux 7 > > Via RHSA-2020:3996 https://access.redhat.com/errata/RHSA-2020:3996 Is this fix valid for Red Hat Enterprise Linux 7.6 ?