A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.
CVSS Details
- CVSS 3.1 Base Score: 6.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade libxml2-staticUpgrade libxml2-pythonUpgrade libxml2-debuginfoUpgrade libxml2-develUpgrade libxml2 | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade libxml2-debuginfoUpgrade libxml2-develUpgrade libxml2-staticUpgrade python3-libxml2-debuginfoUpgrade python3-libxml2Upgrade libxml2Upgrade libxml2-debugsource | Mar 9, 2026 | Feb 2, 2026 |
| Debian | — | Upgrade libxml2 | Jun 9, 2026 | Jun 9, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 2, 2026 |
| Suse | — | Upgrade python311-libxml2Upgrade libxml2-docUpgrade python-libxml2Upgrade python3-libxml2Upgrade libxml2-2Upgrade libxslt-develUpgrade libxml2-2-32bitUpgrade libexslt0Upgrade libxml2-develUpgrade libxml2-devel-32bitUpgrade libxslt1Upgrade python3-libxml2-pythonUpgrade python313-libxml2Upgrade libxslt-toolsUpgrade libxml2-tools | Feb 18, 2026 | Feb 17, 2026 |
| Ubuntu | — | Upgrade libxml2-sourceUpgrade python3-libxml2Upgrade libxml2-utilsUpgrade libxml2-16Upgrade libxml2-dev | Jun 23, 2026 | Jun 22, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 29, 2026 | Feb 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub