Executive brief
A security flaw was found in libxml2, a widely used library for processing XML data. The library's RelaxNG parser fails to limit how deeply it can process nested schema files, which can be exploited by providing a specially crafted, overly complex file. If exploited, this could cause the application using the library to crash, leading to a denial-of-service (DoS) condition.
Technical details
A vulnerability classified as uncontrolled recursion (CWE-674) exists in the RelaxNG parser of libxml2. The issue stems from the parser's failure to enforce a maximum depth limit when resolving nested <include> directives within RelaxNG schemas. An attacker can provide a specially crafted schema with a large linear chain of inclusions to trigger excessive recursion, leading to stack exhaustion and an application crash. This is a remote attack vector, though it typically requires the target application to attempt validation against an attacker-supplied or untrusted schema. Red Hat has released updates for various products (e.g., RHSA-2026:7519) to address this issue.
Affected products
- GNOME libxml2 All versions prior to fix
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat JBoss Core Services 1
- Red Hat Red Hat OpenShift Container Platform 4
Timeline
- 2026-01-15: disclosed: Vulnerability reported and CVE assigned
- 2026-04-10: patched: Red Hat issued security advisory RHSA-2026:7519
References
- https://catalog.redhat.com/software/containers/
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html
- https://access.redhat.com/errata/RHSA-2026:7519
- https://access.redhat.com/security/cve/CVE-2026-0989
- https://bugzilla.redhat.com/show_bug.cgi?id=2429933
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/998