libxml2-2.9.13-14.el9_8.4

エラータID: AXSA:2026-1716:08

Release date: 
Tuesday, September 1, 2026 - 17:35
Subject: 
libxml2-2.9.13-14.el9_8.4
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

The libxml2 library is a development toolbox providing the implementation of various XML standards.

Security Fix(es):

* libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free (CVE-2026-6653)
* libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow (CVE-2026-11979)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-11979
libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process. This issue has been fixed in the commit c2e233fc. NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.
CVE-2026-6653
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. libxml2-2.9.13-14.el9_8.4.src.rpm
    MD5: 221cae807f95040ce805f8ce0deca686
    SHA-256: ea97e66024515fc42ce3cf276023807e2b807f754c623739778687791509ce51
    Size: 3.16 MB

Asianux Server 9 for x86_64
  1. libxml2-2.9.13-14.el9_8.4.i686.rpm
    MD5: 412ca8f772f04cd3b87594db007bd753
    SHA-256: c510522498784cf8e6ad4dce97e6a86985ad8697e80632a78f39ffcbab605afb
    Size: 784.17 kB
  2. libxml2-2.9.13-14.el9_8.4.x86_64.rpm
    MD5: 94ef5d88e30c9a6381195697a1afce0f
    SHA-256: daf268cdbe30796acfef7fb9cbeab086379ed08ca0745919c89b0b0d64507cc1
    Size: 746.74 kB
  3. libxml2-devel-2.9.13-14.el9_8.4.i686.rpm
    MD5: 2edf40315f4bc11a78508af0ca254082
    SHA-256: 9f75da728b353b53cbf05af16d99f8d4a8568f1262dfd95f39df280360eaeec3
    Size: 900.53 kB
  4. libxml2-devel-2.9.13-14.el9_8.4.x86_64.rpm
    MD5: 19590e69e8e9c877c0e3ad5ef6ce2464
    SHA-256: 021648dc96e8db3fcbc24f276608d7f311cbdbc4930ce9b7190ccc35014e7e51
    Size: 900.34 kB
  5. python3-libxml2-2.9.13-14.el9_8.4.x86_64.rpm
    MD5: 621d8505d5c819846cc9f0a299e3f329
    SHA-256: e9c0d11ae90aa7fa5ccc544d97db69ee1aa32d58386f060c3c531d5d1170466f
    Size: 225.12 kB