Bug 2539279 (CVE-2026-96889, RUSTSEC-2026-0305)
| Summary: | CVE-2026-96889 librsvg: Use-after-free when XML includes have duplicated entities | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | akito5623, rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2539674, 2539673, 2539685 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-09-23 09:29:37 UTC
A public proof-of-concept for CVE-2026-96889 has been released: https://github.com/rafabd1/VectorFreed Red Hat CVE page: https://access.redhat.com/security/cve/cve-2026-96889 The published PoC reproduces the librsvg use-after-free involving nested XInclude processing and duplicate XML entity declarations. The researcher also states that command execution has been achieved in multiple downstream application paths, although a universal end-to-end RCE PoC is not currently public. Since a working UAF PoC is now publicly available, could Red Hat Product Security please re-evaluate the impact and remediation priority for affected RHEL packages? In particular, please confirm whether: - affected RHEL packages reproduce the issue with the public PoC; - exploitation may lead to arbitrary code execution when attacker-controlled SVG content is processed; - security updates are planned for affected RHEL releases. |