{
  "threat_severity" : "Moderate",
  "public_date" : "2026-06-22T12:40:31Z",
  "bugzilla" : {
    "description" : "libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free",
    "id" : "2491354",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2491354"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.9",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-416",
  "details" : [ "Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.", "A flaw was found in libxml2. A remote attacker can exploit a use-after-free vulnerability in the `xmlParseInternalSubset` function by providing maliciously crafted XML input. This improper handling of entity resolution can lead to a denial-of-service (DoS), making the affected system or application unavailable." ],
  "statement" : "This Moderate impact use-after-free vulnerability in libxml2 can lead to a denial of service in Red Hat products that process untrusted XML input. In the worst-case scenario, a remote attacker is able to provide specially crafted XML, which, if parsed by an affected application, could cause the application to crash.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-08-31T00:00:00Z",
    "advisory" : "RHSA-2026:61247",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "libxml2-0:2.9.13-14.el9_8.4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-08-31T00:00:00Z",
    "advisory" : "RHSA-2026:61247",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "libxml2-0:2.9.13-14.el9_8.4"
  }, {
    "product_name" : "Red Hat Discovery 2",
    "release_date" : "2026-08-31T00:00:00Z",
    "advisory" : "RHSA-2026:61783",
    "cpe" : "cpe:/a:redhat:discovery:2::el9",
    "package" : "discovery/discovery-server-rhel9:1788205779"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Not affected",
    "package_name" : "libxml2",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "libxml2",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Not affected",
    "package_name" : "libxml2",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Fix deferred",
    "package_name" : "libxml2",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "fix_state" : "Not affected",
    "package_name" : "libxml2",
    "cpe" : "cpe:/a:redhat:hummingbird:1"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift/ose-rhel-coreos-8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift/ose-rhel-coreos-9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-6653\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6653\nhttps://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260\nhttps://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058" ],
  "name" : "CVE-2026-6653",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\nUpdating to a fixed version of libxml2 (2.11.0 or later upstream, or a future RHEL errata) will fully resolve this issue.",
    "lang" : "en:us"
  },
  "csaw" : false
}