Fedora Account System
Red Hat Associate
Red Hat Customer
Librsvg uses libxml2, a C library, to parse XML. When librsvg parses an SVG document which has a nested Xinclude, an XML entity declaration with a duplicate name as an existing one can cause a use-after-free error. While libxml2 is expanding an internal entity, a recursive XInclude can parse another document that declares an entity with the same name. Both parses use the same `XmlState` entity map on the librsvg side. `entity_insert()` replaces the first entry, whose `Drop` implementation calls `xmlFreeNode()`. The outer `xmlCtxtParseEntity()` then keeps using the freed 144-byte `xmlEntity`. The included parse should not free an entity that the outer parser is still using. The fix is in commit 8a1b0cd319e9af2d1e9cf878081dd77f227a0504, where librsvg will no longer free xmlEntity pointers that libxml2 is still using.
A public proof-of-concept for CVE-2026-96889 has been released: https://github.com/rafabd1/VectorFreed Red Hat CVE page: https://access.redhat.com/security/cve/cve-2026-96889 The published PoC reproduces the librsvg use-after-free involving nested XInclude processing and duplicate XML entity declarations. The researcher also states that command execution has been achieved in multiple downstream application paths, although a universal end-to-end RCE PoC is not currently public. Since a working UAF PoC is now publicly available, could Red Hat Product Security please re-evaluate the impact and remediation priority for affected RHEL packages? In particular, please confirm whether: - affected RHEL packages reproduce the issue with the public PoC; - exploitation may lead to arbitrary code execution when attacker-controlled SVG content is processed; - security updates are planned for affected RHEL releases.