https://seclists.org/oss-sec/2026/q2/996: CVE-2026-6653: libxml2: use after fe in xmlParseInternalSubset (>=2.9.11, <2.11.0)
Published Jun 22, 2026
·Updated
Affected Software
1 affected component
Gnome libxml2>=2.9.11<2.11.0
Frequently Asked Questions
1
What is the severity of CVE-2026-6653?
The severity of CVE-2026-6653 is classified as medium.
2
Which versions of libxml2 are affected by CVE-2026-6653?
CVE-2026-6653 affects libxml2 versions from 2.9.11 to less than 2.11.0.
3
How do I fix CVE-2026-6653?
To fix CVE-2026-6653, upgrade libxml2 to a version higher than 2.11.0.
4
What causes the vulnerability CVE-2026-6653?
CVE-2026-6653 is caused by a use after free issue in the xmlParseInternalSubset function.
5
Who reported the CVE-2026-6653 vulnerability?
The CVE-2026-6653 vulnerability was reported by Geoffrey Humphreys.