Back

HIGH

libxml: use-after-free in xmlXIncludeAddNode

Published Jan 26, 2025

Description

xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.

Affected products

Remediation

Red Hat statement

This vulnerability marked as moderate instead of important because memory allocation failures are not typically controllable by an attacker, limiting their exploitability. While improper handling of malloc failures can lead to crashes, memory leaks, or inconsistent states, it does not directly result in privilege escalation or arbitrary code execution. Additionally, in most real-world scenarios, failures due to memory exhaustion occur under extreme system stress rather than as part of an intentional attack vector.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Jan 26, 2025
Updated Nov 3, 2025
Reserved Jan 26, 2025

CISA Vulnrichment

Updated Jan 27, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Jan 26, 2025
Bugzilla 2342118

ENISA EUVD

Assigner mitre
Published Jan 26, 2025
Updated Nov 3, 2025

GitHub

No data