RHSA-2026:60394: Moderate: libxml2 security update
Moderate: libxml2 security update
Other sources
The libxml2 library is a development toolbox providing the implementation of various XML standards.Security Fix(es): libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow (CVE-2026-11979) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libxml2to a version that resolves this vulnerability.Fixed in 2.12.5-10.el10_2.3 - Upgrade
Upgrade
redhat/libxml2-debuginfoto a version that resolves this vulnerability.Fixed in 2.12.5-10.el10_2.3 - Upgrade
Upgrade
redhat/libxml2-debugsourceto a version that resolves this vulnerability.Fixed in 2.12.5-10.el10_2.3 - Upgrade
Upgrade
redhat/libxml2-develto a version that resolves this vulnerability.Fixed in 2.12.5-10.el10_2.3 - Upgrade
Upgrade
redhat/python3-libxml2to a version that resolves this vulnerability.Fixed in 2.12.5-10.el10_2.3 - Upgrade
Upgrade
redhat/python3-libxml2-debuginfoto a version that resolves this vulnerability.Fixed in 2.12.5-10.el10_2.3 - Upgrade
Upgrade
redhat/libxml2to a version that resolves this vulnerability.Fixed in 2.12.5-10.el10_2.3.aa - Upgrade
Upgrade
redhat/libxml2-debuginfoto a version that resolves this vulnerability.Fixed in 2.12.5-10.el10_2.3.aa - Upgrade
Upgrade
redhat/libxml2-debugsourceto a version that resolves this vulnerability.Fixed in 2.12.5-10.el10_2.3.aa - Upgrade
Upgrade
redhat/libxml2-develto a version that resolves this vulnerability.Fixed in 2.12.5-10.el10_2.3.aa - Upgrade
Upgrade
redhat/python3-libxml2to a version that resolves this vulnerability.Fixed in 2.12.5-10.el10_2.3.aa - Upgrade
Upgrade
redhat/python3-libxml2-debuginfoto a version that resolves this vulnerability.Fixed in 2.12.5-10.el10_2.3.aa - Upgrade
Upgrade
redhat/libxml2-staticto a version that resolves this vulnerability.Fixed in 2.12.5-10.el10_2.3 - Upgrade
Upgrade
redhat/libxml2-staticto a version that resolves this vulnerability.Fixed in 2.12.5-10.el10_2.3.aa - Compensating control
Apply the libxml2 security update referenced by the Red Hat advisory article to address CVE-2026-11979 (arbitrary code execution in xmlcatalog utility via buffer overflow).
Event History
Frequently Asked Questions
Which Red Hat Enterprise Linux architectures are covered by this advisory?
The advisory covers x86_64, ARM 64, IBM z Systems, and Power little endian offerings. Coverage includes standard RHEL subscriptions as well as several Extended Update Support, Extended Life Cycle, and x86_64 four-years-of-updates channels.
Is the CodeReady Linux Builder repository included?
Yes. Red Hat CodeReady Linux Builder for Power, little endian is included, including its Extended Update Support offering.