当启用 Python 绑定的 libxml2 中存在一个缺陷。远程攻击者可以通过提供一个包含枚举属性值的文档类型定义(DTD)的精心构造的 XML 文档来利用此漏洞。这会在 SAX attributeDecl 回调处理器中触发双重释放(double-free)错误,即同一个字符串被释放了两次。该缺陷可能导致使用 libxml2 SAX 绑定的 Python 应用发生可复现的崩溃,从而引发拒绝服务(DoS)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Enterprise Linux 6 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Hardened Images | any |
unknown |
any |
unknown | ||
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
unaffected |
any |
unaffected | ||
any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78234 | 9.9 CRITICAL | Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificat |
| CVE-2026-80219 | 8.7 HIGH | Hawtio-operator: hawtio-operator: oauthclient created with grantmethod auto and no secret |
| CVE-2026-77968 | 8.2 HIGH | Hawtio-operator: hawtio-operator: cluster-wide secrets read/write granted to operator serv |
| CVE-2026-76561 | 7.2 HIGH | Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile con |
| CVE-2026-74859 | 6.8 MEDIUM | Gnome-tweaks: path traversal in theme installer |
| CVE-2026-18090 | 6.1 MEDIUM | Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle block |
| CVE-2026-86564 | 3.3 LOW | Dpdk: dpdk: missing length validation before reading command_data in virtio-net control qu |
No comments yet