Impact
A flaw in libxml2 causes a null pointer dereference when parsing an XML catalog that contains a nextCatalog element without the mandatory catalog attribute. The dereference leads to a crash, terminating the process and providing a denial‑of‑service condition. The vulnerability is triggered by a specially crafted XML document and can be invoked by a local user or an attacker who can supply such a catalog to the application.
Affected Systems
Red Hat Enterprise Linux 6 through 10, Red Hat Hardened Images, and Red Hat OpenShift Container Platform 4. The flaw resides in the libxml2 library, which is bundled with many Red Hat distributions and container platforms. No specific version numbers are listed, so any deployment that relies on a vulnerable libxml2 build may be affected.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not yet widely exploited. The attack vector is inferred to be local or through untrusted input; an attacker can induce a crash by providing a malicious catalog file or document. While the impact is limited to service availability for the affected application, repeated crashes could disrupt critical services.
OpenCVE Enrichment
Ubuntu USN