PT-2026-53257 · Libxml2+1 · Libxml2+1

·

CVE-2026-11979

·

Published

2026-06-29

·

Updated

2026-08-31

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libxml2 (affected versions not specified)
Description The xmlcatalog utility is susceptible to multiple stack-based buffer overflows when operating in --shell mode. The usershell() function processes user input using fixed-size stack buffers without adequate bounds checking. An attacker can trigger memory corruption within the stack frame by providing an excessively long input line, which overflows the command, arg, and argv internal buffers during parsing. This may lead to a process crash or arbitrary code execution within the context of the xmlcatalog process.
Recommendations Apply the fix provided in commit c2e233fc. As a temporary mitigation, avoid running the xmlcatalog utility in --shell mode.

Exploit

Fix

DoS

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:60394
ALSA-2026:61247
ALSA-2026:61248
CVE-2026-11979
ECHO-EB03-65DA-1E8C
OESA-2026-3039
OPENSUSE-SU-2026:11258-1
OPENSUSE-SU-2026:21317-1
RHSA-2026:33840
RHSA-2026:60394
RHSA-2026:61247
RHSA-2026:61248
SUSE-SU-2026:22596-1
SUSE-SU-2026:22636-1
SUSE-SU-2026:22806-1
SUSE-SU-2026:22894-1
SUSE-SU-2026:3095-1
SUSE-SU-2026:3096-1
SUSE-SU-2026:3097-1
SUSE-SU-2026:3111-1

Affected Products

Rocky Linux
Libxml2