CVE-2026-6653: libxml2: Use after free in xmlParseInternalSubset via improper entity resolution handling
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in 2.11.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6653?
CVE-2026-6653 has a high severity rating of 7 according to the CVSS score.
How do I fix CVE-2026-6653?
To fix CVE-2026-6653, upgrade to the latest version of libxml2 beyond version 2.11.0.
What type of vulnerability is CVE-2026-6653?
CVE-2026-6653 is a Use After Free vulnerability due to improper entity resolution handling in libxml2.
What impact does CVE-2026-6653 have?
CVE-2026-6653 allows a remote attacker to cause a denial of service through maliciously crafted XML input.
Which versions of libxml2 are affected by CVE-2026-6653?
CVE-2026-6653 affects GNOME libxml2 versions from 2.9.11 to 2.11.0.