PT-2026-53257 · Libxml2+1 · Libxml2+1
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libxml2 (affected versions not specified)
Description
The xmlcatalog utility is susceptible to multiple stack-based buffer overflows when operating in
--shell mode. The usershell() function processes user input using fixed-size stack buffers without adequate bounds checking. An attacker can trigger memory corruption within the stack frame by providing an excessively long input line, which overflows the command, arg, and argv internal buffers during parsing. This may lead to a process crash or arbitrary code execution within the context of the xmlcatalog process.Recommendations
Apply the fix provided in commit c2e233fc.
As a temporary mitigation, avoid running the xmlcatalog utility in
--shell mode.Exploit
Fix
DoS
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rocky Linux
Libxml2