Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.

Project Subscriptions

Vendors Products
Canonical Subscribe
Ubuntu Linux Subscribe
Debian Linux Subscribe
Opensuse Subscribe
Ansible Tower Subscribe
Enterprise Linux Subscribe
Enterprise Linux Desktop Subscribe
Enterprise Linux Server Subscribe
Enterprise Linux Workstation Subscribe
Jboss Core Services Subscribe
Rhel Extras Subscribe
Linux Enterprise Subscribe
Xmlsoft Subscribe
Libxml2 Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-691-1 libxml2 security update
Debian DSA Debian DSA DSA-3637-1 chromium-browser security update
Debian DSA Debian DSA DSA-3744-1 libxml2 security update
EUVD EUVD EUVD-2016-6082 Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
Ubuntu USN Ubuntu USN USN-3041-1 Oxide vulnerabilities
Ubuntu USN Ubuntu USN USN-3235-1 libxml2 vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://googlechromereleases.blogspot.com/2016/07/stable-channel-update.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2016/Sep/msg00008.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2016/Sep/msg00010.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2016/Sep/msg00011.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00020.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00021.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00022.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00028.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2016-1485.html cve-icon cve-icon
http://www.debian.org/security/2016/dsa-3637 cve-icon cve-icon
http://www.securityfocus.com/bid/92053 cve-icon cve-icon
http://www.securitytracker.com/id/1036428 cve-icon cve-icon
http://www.securitytracker.com/id/1038623 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-3041-1 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=1358641 cve-icon cve-icon
https://codereview.chromium.org/2127493002 cve-icon cve-icon
https://crbug.com/623378 cve-icon cve-icon
https://googlechromereleases.blogspot.com/2016/07/stable-channel-update.html cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2016-5131 cve-icon
https://security.gentoo.org/glsa/201610-09 cve-icon cve-icon
https://security.gentoo.org/glsa/201701-37 cve-icon cve-icon
https://source.android.com/security/bulletin/2017-05-01 cve-icon cve-icon
https://support.apple.com/HT207141 cve-icon cve-icon
https://support.apple.com/HT207142 cve-icon cve-icon
https://support.apple.com/HT207143 cve-icon cve-icon
https://support.apple.com/HT207170 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2016-5131 cve-icon
History

Thu, 04 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2025-12-04T16:49:22.168Z

Reserved: 2016-05-31T00:00:00.000Z

Link: CVE-2016-5131

cve-icon Vulnrichment

Updated: 2024-08-06T00:53:48.303Z

cve-icon NVD

Status : Deferred

Published: 2016-07-23T19:59:13.767

Modified: 2025-12-04T17:15:49.963

Link: CVE-2016-5131

cve-icon Redhat

Severity : Important

Publid Date: 2016-07-20T00:00:00Z

Links: CVE-2016-5131 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses