Use After Free Vulnerability in libxml2 Affects GNOME Software
CVE-2026-6653

7HIGH

Key Information:

Vendor

Gnome

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-6653?

A vulnerability exists in the libxml2 library affecting GNOME versions 2.9.11 to 2.11.0, wherein improper entity resolution handling in the xmlParseInternalSubset function can be exploited by a remote attacker. Maliciously crafted XML input may lead to a denial-of-service condition, potentially disrupting the application utilizing this library. This highlights the need for timely updates and security measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

libxml2 2.9.11 < 2.11.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Geoffrey Humphreys
.