Impact
A flaw (CWE‑763) exists in libxml2 when Python bindings are enabled. A remote attacker can supply a crafted XML document that includes a DTD with enumerated attribute values. This causes the SAX attributeDecl callback to free a string twice, leading to a null pointer dereference and a crash. The result is a denial‑of‑service because the affected Python application will terminate.
Affected Systems
Red Hat’s Red Enterprise Linux 6, 7, 8, 9, and 10, Red Hat Hardened Images, and Red Hat OpenShift Container Platform 4 are affected when libxml2 with Python bindings is used.
Risk and Exploitability
The CVSS score of 8.5 marks this flaw as high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is remote: an attacker can send a malicious XML payload to a vulnerable Python program that uses libxml2 with the bindings enabled. Because the flaw leads only to a crash and not to arbitrary code execution, the primary risk is a denial of service to the affected service or application. However, repeated crashes could be leveraged in a larger denial‑of‑service campaign, especially in a managed platform environment such as OpenShift.
OpenCVE Enrichment