CVE-2023-28484: Debian Linux

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Xmlsoft LIBXML2: before 2.10.4 (fixed in 2.10.4)

Published 2023-04-24. Last modified 2026-06-17.