Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-6732

Опубликовано: 23 апр. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxml2fixed2.15.3+dfsg-1package
libxml2not-affectedtrixiepackage
libxml2not-affectedbookwormpackage
libxml2not-affectedbullseyepackage

Примечания

  • https://gitlab.gnome.org/GNOME/libxml2/-/issues/1097

  • https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/411

  • Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/226b560837b90dea9b14431eca6e6fda8fb01ab4 (master)

  • Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/7cea3fd1557437b88f2c7b5e1b71a2d5fb152b55 (master)

  • Introduced with: https://gitlab.gnome.org/GNOME/libxml2/-/commit/e1153832b0a31b872517ab582641630e2d14cec7 (v2.13.0)

EPSS

Процентиль: 47%
0.00632
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.

CVSS3: 6.5
redhat
4 месяца назад

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.

CVSS3: 6.5
nvd
3 месяца назад

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.

msrc
3 месяца назад

Libxml2: libxml2: denial of service via crafted xsd-validated document

CVSS3: 6.5
github
3 месяца назад

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.

EPSS

Процентиль: 47%
0.00632
Низкий