An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-10
https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-06
https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-04
https://cert-portal.siemens.com/productcert/html/ssa-556635.html
https://support.apple.com/en-us/HT213535
https://support.apple.com/en-us/HT213531
https://support.apple.com/kb/HT213536
https://support.apple.com/kb/HT213535
https://support.apple.com/kb/HT213534
https://support.apple.com/kb/HT213533
https://support.apple.com/kb/HT213531
https://security.netapp.com/advisory/ntap-20221209-0003/
https://gitlab.gnome.org/GNOME/libxml2/-/tags/v2.10.3
https://gitlab.gnome.org/GNOME/libxml2/-/tags
https://gitlab.gnome.org/GNOME/libxml2/-/commit/1b41ec4e9433b05bb0376be4725804c54ef1d80b
http://seclists.org/fulldisclosure/2022/Dec/27
http://seclists.org/fulldisclosure/2022/Dec/26
http://seclists.org/fulldisclosure/2022/Dec/25