libxml2-2.9.7-21.el8_10.7
エラータID: AXSA:2026-1714:07
The libxml2 library is a development toolbox providing the implementation of various XML standards.
Security Fix(es):
* libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow (CVE-2026-11979)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-11979
libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process. This issue has been fixed in the commit c2e233fc. NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.
Update packages.
libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process. This issue has been fixed in the commit c2e233fc. NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.
N/A
SRPMS
- libxml2-2.9.7-21.el8_10.7.src.rpm
MD5: 0ab8438651c9c20a59fd0aee23a660cd
SHA-256: ab5f5c694da12ae4357578d2533abd9c74c2380478e6c20411f90cca1b49a214
Size: 5.25 MB
Asianux Server 8 for x86_64
- libxml2-2.9.7-21.el8_10.7.i686.rpm
MD5: 96622c4da80e50a29d8dab6d72b4bed3
SHA-256: 5c0e177922944590f7d770e1590241945f5cc57a16ed188ed42dce01e02ff644
Size: 742.80 kB - libxml2-2.9.7-21.el8_10.7.x86_64.rpm
MD5: 9535f1b7865325a298282408095a6cbb
SHA-256: 2aad397104c538104fb9c7c0964f02740333961fa6024fba051fba87776683e0
Size: 697.60 kB - libxml2-devel-2.9.7-21.el8_10.7.i686.rpm
MD5: bed103a50a21058d0d4aca22e1bd7da4
SHA-256: 8c7a2af20185d6d8cdfb2f221d3dcbbce39e33a66b547ee5caeefcb3be09fa9d
Size: 1.04 MB - libxml2-devel-2.9.7-21.el8_10.7.x86_64.rpm
MD5: 6138b31e8a023cf9b24d0d832de9c5f3
SHA-256: c4fa479999e374a9eead79ace3f784f3d3ded9815ced947a880ad7efd35cc553
Size: 1.04 MB - python3-libxml2-2.9.7-21.el8_10.7.x86_64.rpm
MD5: fada91feecf76433fcc26b0cdfa1eb68
SHA-256: 0e0a5b2c1062a27f5731cdbcacc2e127c9a808f0dec23d843b5c910b8b933b77
Size: 237.86 kB