Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-11979

Опубликовано: 29 июн. 2026
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS3: 7.8

Описание

libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process. This issue has been fixed in the commit c2e233fc. NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.

РелизСтатусПримечание
devel

ignored

see notes
esm-infra-legacy/trusty

ignored

see notes
esm-infra-legacy/xenial

ignored

see notes
esm-infra/bionic

ignored

see notes
esm-infra/focal

ignored

see notes
jammy

ignored

see notes
noble

ignored

see notes
questing

ignored

end of life, was ignored [see notes]
resolute

ignored

see notes
upstream

needs-triage

Показывать по

EPSS

Процентиль: 5%
0.00148
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 4.8
redhat
около 2 месяцев назад

libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process. This issue has been fixed in the commit c2e233fc. NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.

CVSS3: 7.8
nvd
около 2 месяцев назад

libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process. This issue has been fixed in the commit c2e233fc. NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.

msrc
около 1 месяца назад

Stack-Based Buffer Overflow in libxml2

CVSS3: 7.8
debian
около 2 месяцев назад

libxml2 is vulnerable to multiple stack-based buffer overflows in the ...

suse-cvrf
27 дней назад

Security update for libxml2

EPSS

Процентиль: 5%
0.00148
Низкий

7.8 High

CVSS3