Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-88149

libxslt version 1.1.34-9.el9_5.2 fails on realloc with segmentation fault when processing oscap xml files

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Critical Critical
    • rhel-9.5.z
    • rhel-9.5.z
    • libxslt
    • None
    • libxslt-1.1.34-9.el9_5.3
    • Yes
    • Critical
    • ZStream
    • rhel-display-desktop-foundation
    • ssg_display
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • x86_64
    • None

      What were you trying to do that didn't work?

      Run `oscap xccdf generate report` on arf or result xml files, or alternatively xsltproc

      What is the impact of this issue to you?

      No longer able to generate oscap html reports.

      Please provide the package NVR for which the bug is seen:

      libxslt-1.1.34-9.el9_5.2 on Red Hat Enterprise Linux release 9.5 (Plow)

      How reproducible is this bug?:

      Always happens on any of my systems since the update to 1.1.34-9.el9_5.2. Systems are hardened and in FIPS mode.  Rolling back to 1.1.34-9.el9_5.1 fixes the issue.

      Steps to reproduce

      1. sudo oscap xccdf eval -profile xccdf_org.ssgproject.content_profile_stig   -results xccdf.xml /usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml 
      2. sudo oscap xccdf generate report xccdf.xml | sudo tee report.html

      Expected results

      openscap report.html generated

      Actual results

      realloc failed

      Segmentation fault

      (gdb shows failure when using libxslt)

              dking@redhat.com David King
              abertolli Angelo Bertolli (Inactive)
              David King David King
              Tomas Pelka Tomas Pelka
              Votes:
              0 Vote for this issue
              Watchers:
              18 Start watching this issue

                Created:
                Updated:
                Resolved: