Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-0989

Опубликовано: 15 янв. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.

Отчет

This vulnerability is rated Low for Red Hat products. The flaw in libxml2's RelaxNG include handling requires attacker-controlled schema input to trigger unbounded recursion, leading to a denial of service. Exploitation is limited to scenarios where applications process untrusted RelaxNG schema files.

Меры по смягчению последствий

To mitigate this issue, restrict applications using libxml2 from processing untrusted RelaxNG schema files. Implement strict input validation and sanitization for all RelaxNG schema inputs to prevent the parsing of maliciously crafted, deeply nested include directives.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libxml2Fix deferred
Red Hat Enterprise Linux 6libxml2Fix deferred
Red Hat Enterprise Linux 7libxml2Fix deferred
Red Hat Enterprise Linux 8libxml2Fix deferred
Red Hat Enterprise Linux 9libxml2Fix deferred
Red Hat JBoss Core Serviceslibxml2Fix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=2429933libxml2: Unbounded RelaxNG Include Recursion Leading to Stack Overflow

EPSS

Процентиль: 5%
0.0002
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
2 месяца назад

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.

CVSS3: 3.7
nvd
2 месяца назад

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk.

msrc
2 месяца назад

Libxml2: unbounded relaxng include recursion leading to stack overflow

CVSS3: 3.7
debian
2 месяца назад

A flaw was identified in the RelaxNG parser of libxml2 related to how ...

suse-cvrf
около 2 месяцев назад

Security update for libxml2

EPSS

Процентиль: 5%
0.0002
Низкий

3.7 Low

CVSS3