rlsa-2026:69655

CVSS 5.9 osv_rocky
Description

The libxml2 library is a development toolbox providing the implementation of various XML standards. Security Fix(es): * libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free (CVE-2026-6653) Bug Fix(es) and Enhancement(s): * libxml2: CVE-2025-9714 fix (Rocky Linux-119279) backported wrong upstream commit ? dyn:map recursion still crashes (JIRA:Rocky Linux-249282) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "source": "https://storage.googleapis.com/resf-osv-data/RLSA-2026:69655.json"
      },
      "package": {
        "ecosystem": "Rocky Linux:8",
        "name": "libxml2",
        "purl": "pkg:rpm/rocky-linux/libxml2?distro=rocky-linux-8&epoch=0"
      },
      "ranges": [
        {
          "database_specific": {
            "yum_repository": "BaseOS"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:2.9.7-21.el8_10.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "credits": [
    {
      "name": "Rocky Enterprise Software Foundation"
    },
    {
      "name": "Red Hat"
    }
  ],
  "database_specific": {
    "license": "CC-BY-4.0",
    "license_url": "https://creativecommons.org/licenses/by/4.0/",
    "source_advisory": "RHSA-2026:69655"
  },
  "details": "The libxml2 library is a development toolbox providing the implementation of various XML standards.\n\nSecurity Fix(es):\n\n* libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free (CVE-2026-6653)\n\nBug Fix(es) and Enhancement(s):\n\n* libxml2: CVE-2025-9714 fix (Rocky Linux-119279) backported wrong upstream commit ? dyn:map recursion still crashes (JIRA:Rocky Linux-249282)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.",
  "id": "RLSA-2026:69655",
  "modified": "2026-09-23T06:30:03.142524500Z",
  "published": "2026-09-23T06:00:55.733679Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://errata.rockylinux.org/RLSA-2026:69655"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491354"
    },
    {
      "type": "ADVISORY",
      "url": "https://access.redhat.com/errata/RHSA-2026:69655"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Moderate: libxml2 security, bug fix, and enhancement update",
  "upstream": [
    "CVE-2026-6653"
  ]
}
View JSON API Download JSON