Bug 2539279 (CVE-2026-96889, RUSTSEC-2026-0305)

Summary: CVE-2026-96889 librsvg: Use-after-free when XML includes have duplicated entities
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: akito5623, rhel-process-autobot, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2539674, 2539673, 2539685    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-23 09:29:37 UTC
Librsvg uses libxml2, a C library, to parse XML.  When librsvg parses
an SVG document which has a nested Xinclude, an XML entity declaration
with a duplicate name as an existing one can cause a use-after-free error.

While libxml2 is expanding an internal entity, a recursive XInclude
can parse another document that declares an entity with the same
name. Both parses use the same `XmlState` entity
map on the librsvg side. `entity_insert()` replaces the first entry, whose `Drop`
implementation calls `xmlFreeNode()`. The outer `xmlCtxtParseEntity()`
then keeps using the freed 144-byte `xmlEntity`.

The included parse should not free an entity that the outer parser is still using.

The fix is in commit 8a1b0cd319e9af2d1e9cf878081dd77f227a0504, where
librsvg will no longer free xmlEntity pointers that libxml2 is still
using.

Comment 2 Akiyoshi Kurita 2026-09-30 02:09:55 UTC
A public proof-of-concept for CVE-2026-96889 has been released:

https://github.com/rafabd1/VectorFreed

Red Hat CVE page:
https://access.redhat.com/security/cve/cve-2026-96889

The published PoC reproduces the librsvg use-after-free involving nested XInclude processing and duplicate XML entity declarations.

The researcher also states that command execution has been achieved in multiple downstream application paths, although a universal end-to-end RCE PoC is not currently public.

Since a working UAF PoC is now publicly available, could Red Hat Product Security please re-evaluate the impact and remediation priority for affected RHEL packages?

In particular, please confirm whether:

- affected RHEL packages reproduce the issue with the public PoC;
- exploitation may lead to arbitrary code execution when attacker-controlled SVG content is processed;
- security updates are planned for affected RHEL releases.