CVE Vulnerabilities

CVE-2026-74860

Release of Invalid Pointer or Reference

Published: Sep 08, 2026 | Modified: Sep 28, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.5 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.

Weakness

The product attempts to return a memory resource to the system, but it calls the wrong release function or calls the appropriate release function incorrectly.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatlibxml2-0:2.12.5-10.el10_2.4*
Red Hat Enterprise Linux 8RedHatlibxml2-0:2.9.7-21.el8_10.9*
Red Hat Enterprise Linux 8RedHatlibxml2-0:2.9.7-21.el8_10.9*
Red Hat Enterprise Linux 9RedHatlibxml2-0:2.9.13-14.el9_8.5*
Red Hat Enterprise Linux 9RedHatlibxml2-0:2.9.13-14.el9_8.5*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/jetstack-cert-manager-rhel9:1790589912*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/cert-manager-istio-csr-rhel9:1790589914*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/cert-manager-operator-rhel9:1790589855*
Red Hat Hardened ImagesRedHatlibxml2-main-2.15.4-0.1.hum1*
Libxml2Ubuntuesm-infra-legacy/trusty*
Libxml2Ubuntuesm-infra-legacy/xenial*
Libxml2Ubuntuesm-infra/bionic*
Libxml2Ubuntuesm-infra/focal*
Libxml2Ubuntujammy*
Libxml2Ubuntunoble*
Libxml2Ubunturesolute*
Libxml2Ubuntuupstream*

Extended Description

This weakness can take several forms, such as:

Potential Mitigations

  • Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.
  • For example, glibc in Linux provides protection against free of invalid pointers.

References