REDHAT-BUG-2494191: Buffer Overflow

Published Jun 29, 2026
·
Updated

libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.

This issue has been fixed in the commit c2e233fc.

NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.

Affected Software

1 affected component
libxml2 libxml2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade libxml2 to a version that resolves this vulnerability.

    Patch c2e233fc

Event History

Jun 29, 2026
Data Sourced
via Red Hat·02:01 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this issue?

The issue affects use of the xmlcatalog utility in --shell mode. The vulnerable input handling is in the usershell() function.

2

What would an attacker need to do to trigger the flaw?

An attacker would need to supply an overly long input line to xmlcatalog while it is running in --shell mode. The oversized line can overflow fixed-size command, argument, and argv stack buffers during parsing.

3

What can be done before an update is available?

Avoid running xmlcatalog in --shell mode with untrusted input. The issue is fixed by commit c2e233fc.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203