Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-6653

Опубликовано: 22 июн. 2026
Источник: debian
EPSS Низкий

Описание

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxml2fixed2.14.5+dfsg-0.1package
libxml2no-dsatrixiepackage
libxml2postponedbookwormpackage
libxml2postponedbullseyepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2026/06/22/3

  • https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058

  • Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/463bbeeca1805b5c4828f50d0fefc4eebaf620df (v2.11.0)

  • Mark 2.14.5+dfsg-0.1 as the first version fixed in unstable as from 2.12.7+dfsg-1

  • the version was reverted back to a 2.9.14 based one.

EPSS

Процентиль: 28%
0.00355
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 1 месяца назад

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

CVSS3: 5.9
redhat
около 1 месяца назад

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

CVSS3: 9.8
nvd
около 1 месяца назад

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

CVSS3: 9.8
github
около 1 месяца назад

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

EPSS

Процентиль: 28%
0.00355
Низкий