CVE-2026-6653

NameCVE-2026-6653
DescriptionUse After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libxml2 (PTS)bullseye2.9.10+dfsg-6.7+deb11u4vulnerable
bullseye (security)2.9.10+dfsg-6.7+deb11u10vulnerable
bookworm2.9.14+dfsg-1.3~deb12u5vulnerable
bookworm (security)2.9.14+dfsg-1.3~deb12u4vulnerable
trixie2.12.7+dfsg+really2.9.14-2.1+deb13u2vulnerable
trixie (security)2.12.7+dfsg+really2.9.14-2.1+deb13u1vulnerable
forky, sid2.15.3+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libxml2source(unstable)2.14.5+dfsg-0.1

Notes

https://www.openwall.com/lists/oss-security/2026/06/22/3
https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058
Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/463bbeeca1805b5c4828f50d0fefc4eebaf620df (v2.11.0)
Mark 2.14.5+dfsg-0.1 as the first version fixed in unstable as from 2.12.7+dfsg-1
the version was reverted back to a 2.9.14 based one.

Search for package or bug name: Reporting problems