Executive brief
A vulnerability in the libxml2 library, which is widely used for processing XML data, can be exploited to cause a denial-of-service condition. By providing a specially crafted XML catalog file, an attacker can force the system to perform redundant calculations, leading to excessive CPU usage. This can slow down or crash applications that rely on this library to process XML files, impacting service availability.
Technical details
An uncontrolled resource consumption vulnerability (CWE-400) exists in libxml2 during the processing of XML catalogs. The flaw is triggered when a catalog contains multiple <nextCatalog> elements pointing to the same downstream catalog, causing the parser to redundantly traverse catalog chains. This results in exponential growth in processing time relative to the depth of the catalog chain. An attacker can exploit this by supplying crafted catalogs, leading to excessive CPU consumption and a denial-of-service (DoS) condition. While the attack vector is listed as local with high complexity in some metrics, it can be triggered via any application interface that allows the loading of external or local XML catalogs. Fixes have been released in various Red Hat distributions and upstream in libxml2.
Affected products
- GNOME libxml2
- Red Hat Red Hat Enterprise Linux 6 affected
- Red Hat Red Hat Enterprise Linux 7 affected
- Red Hat Red Hat Enterprise Linux 8 affected
- Red Hat Red Hat Enterprise Linux 9 affected
- Red Hat Red Hat Enterprise Linux 10 affected
- Red Hat Red Hat Hardened Images unaffected starting from 2.15.2-0.3.hum1
- Red Hat Red Hat JBoss Core Services affected
- Red Hat Red Hat OpenShift Container Platform 4 affected
Timeline
- 2026-01-15: disclosed: Initial vulnerability report and CVE assignment
- 2026-01-15: advisory: NVD and Red Hat published initial details
- 2026-04-10: patched: Red Hat released security advisory RHSA-2026:7519 with fixes
References
- https://catalog.redhat.com/software/containers/
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html
- https://access.redhat.com/errata/RHSA-2026:7519
- https://access.redhat.com/security/cve/CVE-2026-0992
- https://bugzilla.redhat.com/show_bug.cgi?id=2429975
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019