RHSA-2026:61248: Moderate: libxml2 security update
Moderate: libxml2 security update
Other sources
The libxml2 library is a development toolbox providing the implementation of various XML standards.Security Fix(es): libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow (CVE-2026-11979) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libxml2to a version that resolves this vulnerability.Fixed in 2.9.7-21.el8_10.7 - Upgrade
Upgrade
redhat/libxml2-debuginfoto a version that resolves this vulnerability.Fixed in 2.9.7-21.el8_10.7 - Upgrade
Upgrade
redhat/libxml2-debugsourceto a version that resolves this vulnerability.Fixed in 2.9.7-21.el8_10.7 - Upgrade
Upgrade
redhat/libxml2-develto a version that resolves this vulnerability.Fixed in 2.9.7-21.el8_10.7 - Upgrade
Upgrade
redhat/python3-libxml2to a version that resolves this vulnerability.Fixed in 2.9.7-21.el8_10.7 - Upgrade
Upgrade
redhat/python3-libxml2-debuginfoto a version that resolves this vulnerability.Fixed in 2.9.7-21.el8_10.7 - Upgrade
Upgrade
redhat/libxml2to a version that resolves this vulnerability.Fixed in 2.9.7-21.el8_10.7.aa - Upgrade
Upgrade
redhat/libxml2-debuginfoto a version that resolves this vulnerability.Fixed in 2.9.7-21.el8_10.7.aa - Upgrade
Upgrade
redhat/libxml2-debugsourceto a version that resolves this vulnerability.Fixed in 2.9.7-21.el8_10.7.aa - Upgrade
Upgrade
redhat/libxml2-develto a version that resolves this vulnerability.Fixed in 2.9.7-21.el8_10.7.aa - Upgrade
Upgrade
redhat/python3-libxml2to a version that resolves this vulnerability.Fixed in 2.9.7-21.el8_10.7.aa - Upgrade
Upgrade
redhat/python3-libxml2-debuginfoto a version that resolves this vulnerability.Fixed in 2.9.7-21.el8_10.7.aa - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Patch CVE-2026-11979
Event History
Frequently Asked Questions
Which component is directly affected by this issue?
The vulnerability is in the xmlcatalog utility provided by libxml2. The listed affected software also includes libxml2 development, debug, and Python 3 bindings packages.
What does exploitation require?
The provided information identifies a buffer overflow in xmlcatalog that can lead to arbitrary code execution. It does not specify the required attacker access, input source, or configuration conditions.
How can I determine whether my systems are affected?
Identify systems running the listed Red Hat libxml2 packages, particularly where the xmlcatalog utility is present or used. The advisory applies to the listed Red Hat Enterprise Linux x86_64 Extended Life Cycle and IBM z Systems offerings.