CVE-2026-11979

NameCVE-2026-11979
Descriptionlibxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process. This issue has been fixed in the commit c2e233fc. NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libxml2 (PTS)bookworm2.9.14+dfsg-1.3~deb12u6vulnerable
bookworm (security)2.9.14+dfsg-1.3~deb12u4vulnerable
trixie2.12.7+dfsg+really2.9.14-2.1+deb13u3vulnerable
trixie (security)2.12.7+dfsg+really2.9.14-2.1+deb13u1vulnerable
sid, forky2.15.4+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libxml2source(unstable)2.15.4+dfsg-1unimportant

Notes

https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1124
https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e
https://gitlab.gnome.org/GNOME/libxml2/-/commit/cd48d441f8fb1cf84e74c393310b72e4534de435 (v2.15.4)
Not considered a security issue upstream

Search for package or bug name: Reporting problems