Description
A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS).
Published: 2026-09-17
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via application crash
Action: Apply Patch
AI Analysis

Impact

A flaw in libxml2 causes a null pointer dereference when parsing an XML catalog that contains a nextCatalog element without the mandatory catalog attribute. The dereference leads to a crash, terminating the process and providing a denial‑of‑service condition. The vulnerability is triggered by a specially crafted XML document and can be invoked by a local user or an attacker who can supply such a catalog to the application.

Affected Systems

Red Hat Enterprise Linux 6 through 10, Red Hat Hardened Images, and Red Hat OpenShift Container Platform 4. The flaw resides in the libxml2 library, which is bundled with many Red Hat distributions and container platforms. No specific version numbers are listed, so any deployment that relies on a vulnerable libxml2 build may be affected.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not yet widely exploited. The attack vector is inferred to be local or through untrusted input; an attacker can induce a crash by providing a malicious catalog file or document. While the impact is limited to service availability for the affected application, repeated crashes could disrupt critical services.

Generated by OpenCVE AI on September 17, 2026 at 20:50 UTC.

Remediation

Vendor Workaround

To mitigate this issue, avoid processing untrusted XML catalog files with applications linked against libxml2. Users should exercise caution when opening or processing XML documents from untrusted sources, as a malicious catalog could lead to application crashes. Where possible, restrict the ability of applications to load external XML catalogs, or ensure that only trusted catalog files are used.


OpenCVE Recommended Actions

  • Apply the latest Red Hat security updates that include the libxml2 patch
  • Restrict or disable loading of external XML catalogs, ensuring only trusted catalog files are used
  • Validate and sanitize XML documents from untrusted sources before processing

Generated by OpenCVE AI on September 17, 2026 at 20:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8910-1 libxml2 vulnerabilities
History

Mon, 21 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
References

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat hardened Images
Redhat libxml2
Redhat openshift Container Platform
Vendors & Products Redhat hardened Images
Redhat libxml2
Redhat openshift Container Platform

Fri, 18 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS).
Title Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute
First Time appeared Redhat
Redhat enterprise Linux
Redhat hummingbird
Redhat openshift
Weaknesses CWE-476
CPEs cpe:/a:redhat:hummingbird:1
cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat hummingbird
Redhat openshift
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Redhat Enterprise Linux Hardened Images Hummingbird Libxml2 Openshift Openshift Container Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-24T11:57:00.431Z

Reserved: 2026-08-19T17:15:10.735Z

Link: CVE-2026-76781

cve-icon Vulnrichment

Updated: 2026-09-17T17:10:18.323Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T16:17:42.070

Modified: 2026-09-24T12:17:12.793

Link: CVE-2026-76781

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:36:56Z

Weaknesses