CVE-2026-11979
Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-121
Desbordamiendo de búfer basado en pila (Stack)
Fecha de publicación:
29/06/2026
Última modificación:
30/06/2026
Descripción
*** Pendiente de traducción *** libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking.<br />
By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame.<br />
Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.<br />
<br />
This issue has been fixed in the commit c2e233fc.<br />
<br />
NOTE:<br />
The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.
Impacto
Puntuación base 4.0
1.80
Gravedad 4.0
BAJA
Puntuación base 3.x
7.80
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* | 2.15.3 (incluyendo) |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página



