GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
https://www.oracle.com/security-alerts/cpuoct2021.html
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpuapr2022.html
https://security.netapp.com/advisory/ntap-20200924-0001/
https://security.gentoo.org/glsa/202107-05
https://lists.debian.org/debian-lts-announce/2020/09/msg00009.html
https://gitlab.gnome.org/GNOME/libxml2/-/issues/178
https://gitlab.gnome.org/GNOME/libxml2/-/commit/50f06b3efb638efb0abd95dc62dca05ae67882c2
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00061.html
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00036.html