Back

HIGH

libxml2: Use after free triggered by XPointer paths beginning with range-to

Published Jul 23, 2016

Description

Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.

Affected products

Remediation

Red Hat statement

This flaw in libxml2 requires exposing the library to XPath/XPointer expressions from an untrusted source, which is not common in practice for applications using libxml2. For libxml2, Red Hat Product Security has rated this vulnerability as Moderate severity.

Metrics

Weaknesses (1)

References (29)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Jul 23, 2016
Updated Dec 4, 2025
Reserved May 31, 2016
CISA Vulnrichment
Updated Dec 4, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 20, 2016