CVE-2026-6653

Published: June 24, 2026Last modified: July 15, 2026

Description

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

Severity score breakdown

ParameterValue
Base score9.8
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibxml2Fixed (2.10.4-r10)
25 LTSlibxml2Not affected (2.13.8-r0)
Streamlibxml2Fixed (2.11.4-r0)
Hardened Containers23 LTSlibxml2Fixed (2.10.4-r10)
25 LTSlibxml2Not affected (2.13.8-r0)
Streamlibxml2Fixed (2.11.4-r0)

References

ON THIS PAGE