libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.
This issue has been fixed in the commit c2e233fc.
NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.
CVSS Details
- CVSS 4.0 Base Score: 1.8 (LOW)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade libxml2-pythonUpgrade libxml2-staticUpgrade libxml2-develUpgrade libxml2-debuginfoUpgrade libxml2 | Aug 5, 2026 | Aug 5, 2026 |
| Amazon_linux_2023 | — | Upgrade libxml2-staticUpgrade python3-libxml2Upgrade libxml2-debuginfoUpgrade libxml2-debugsourceUpgrade libxml2-develUpgrade libxml2Upgrade python3-libxml2-debuginfo | Aug 10, 2026 | Jun 29, 2026 |
| Redhat_linux | — | No solution existsUpgrade libxml2-staticUpgrade libxml2-develUpgrade libxml2-debugsourceUpgrade libxml2Upgrade python3-libxml2Upgrade python3-libxml2-debuginfoUpgrade libxml2-debuginfo | Jul 17, 2026 | Jun 29, 2026 |
| Rocky_linux | — | Upgrade libxml2Upgrade libxml2-develUpgrade python3-libxml2-debuginfoUpgrade libxml2-debugsourceUpgrade python3-libxml2Upgrade libxml2-debuginfo | Aug 31, 2026 | Aug 28, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 13, 2026 | Jun 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub