Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-96889— Librsvg: use-after-free when xml includes have duplicated entities

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 librsvg 中发现了一个缺陷。当处理包含嵌套 XML 包含(XInclude)且具有重复实体声明的 SVG 文档时,可能会发生释放后使用(use-after-free)错误。该漏洞的产生原因是库错误地释放了仍被解析器使用的 XML 实体。攻击者可能利用此漏洞导致拒绝服务(DoS)或执行任意代码。

CVSS 7.8 · High EPSS 0.13% · P2
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-96889

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Librsvg: use-after-free when xml includes have duplicated entities
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
释放后使用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-96889

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-96889

请登录查看更多情报信息。

Other References for CVE-2026-96889 (1)

Other References for CVE-2026-96889 (4)

Same Patch Batch · Red Hat · 2026-09-23 · 46 CVEs total

CVE-2026-84474 9.9 CRITICAL Automation-controller: automation-controller-container: automation-controller: view_jobtem
CVE-2026-84502 9.9 CRITICAL Automation-controller: automation-controller-container: automation-controller: project scm
CVE-2026-84719 9.9 CRITICAL Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitiz
CVE-2026-75884 9.1 CRITICAL Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in c
CVE-2026-96275 8.8 HIGH Flatpak: flatpak: arbitrary write access as root via extra-data extraction
CVE-2026-84683 8.7 HIGH Automation-controller: automation-controller-container: automation-controller: stored cros
CVE-2026-84691 8.7 HIGH Automation-controller: automation-controller-container: automation-controller: format stri
CVE-2026-76648 8.5 HIGH Automation-controller: automation-controller-container: aap controller: copyapiview.post()
CVE-2026-84486 8.2 HIGH Automation-controller: automation-controller-container: automation-controller: unauthentic
CVE-2026-96512 7.8 HIGH Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authori
CVE-2026-84499 7.7 HIGH Automation-controller: automation-controller-container: automation-controller: write-only
CVE-2026-84706 7.6 HIGH Automation-controller: automation-controller-container: automation-controller: credential
CVE-2026-96541 7.5 HIGH Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake d
CVE-2026-75887 7.5 HIGH Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handle
CVE-2026-88830 7.5 HIGH Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pr
CVE-2026-88832 7.3 HIGH Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label
CVE-2026-85475 7.2 HIGH Automation-controller: automation-controller-container: automation-controller: rsyslog con
CVE-2026-75886 7.2 HIGH Openshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalogd
CVE-2026-84714 7.1 HIGH Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jin
CVE-2026-96445 6.8 MEDIUM Keycloak-services: keycloak-services: conditional otp skip-header policy evaluated against

Showing top 20 of 46 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-96889

No comments yet


Leave a comment