Red Hat Enterprise Linux 10 vulnerability

A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS).

Published 17 Sep 2026Updated 18 Sep 20264 sources
CVSS 5.5

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.