Description

A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.

INFO

Published Date :

2026-02-02T12:38:14.588Z

Last Modified :

2026-04-22T09:30:49.350Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2026-1757 vulnerability.

Vendors Products
Redhat
  • Enterprise Linux
  • Hummingbird
  • Jboss Core Services
  • Openshift

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact