Description
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
Severity (CVSS)
| Base score | 7 |
|---|---|
| Severity | High |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P |
| Provided by | CNA |
Weaknesses
- CWE-416 — CWE-416 Use after free
- CWE-611 — CWE-611 Improper Restriction of XML External Entity Processing
Affected products
| Vendor | Product | Versions |
|---|---|---|
| GNOME | libxml2 | 2.9.11 to <2.11.0 |
References
- https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260 (issue-tracking)
- https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058 (issue-tracking)
Generated from the official CVE List on 22 Jun 2026 14:43 UTC.