Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
CVSS Details
- CVSS 4.0 Base Score: 7 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade libxml2Upgrade libxml2-staticUpgrade libxml2-develUpgrade libxml2-pythonUpgrade libxml2-debuginfo | Jul 8, 2026 | Jul 8, 2026 |
| Amazon_linux_2023 | — | Upgrade libxml2-debugsourceUpgrade python3-libxml2-debuginfoUpgrade libxml2-develUpgrade libxml2Upgrade libxml2-debuginfoUpgrade python3-libxml2Upgrade libxml2-static | Jul 8, 2026 | Jun 22, 2026 |
| Redhat_linux | — | Upgrade python3-libxml2-debuginfoUpgrade libxml2Upgrade libxml2-debugsourceUpgrade python3-libxml2Upgrade libxml2-develUpgrade libxml2-debuginfo | Jul 17, 2026 | Jun 22, 2026 |
| Rocky_linux | — | Upgrade libxml2Upgrade python3-libxml2Upgrade libxml2-develUpgrade libxml2-debugsourceUpgrade libxml2-debuginfoUpgrade python3-libxml2-debuginfo | Sep 2, 2026 | Aug 31, 2026 |
| Ubuntu | — | Upgrade libxml2Upgrade libxml2-devUpgrade libxml2-utilsUpgrade python3-libxml2 | Jun 24, 2026 | Jun 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub