Bug 2539685 - CVE-2026-96889 rust-librsvg: Use-after-free when XML includes have duplicated entities [fedora-all]
Summary: CVE-2026-96889 rust-librsvg: Use-after-free when XML includes have duplicated...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: rust-librsvg
Version: rawhide
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Rust SIG
QA Contact:
URL:
Whiteboard: {"flaws": ["04dbfa90-5b9c-462c-9f29-0...
Depends On:
Blocks: CVE-2026-96889, RUSTSEC-2026-0305
TreeView+ depends on / blocked
 
Reported: 2026-09-23 19:22 UTC by Samuele Negrini
Modified: 2026-09-27 20:17 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-09-27 20:17:59 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Samuele Negrini 2026-09-23 19:22:12 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Librsvg uses libxml2, a C library, to parse XML.  When librsvg parses
an SVG document which has a nested Xinclude, an XML entity declaration
with a duplicate name as an existing one can cause a use-after-free error.

While libxml2 is expanding an internal entity, a recursive XInclude
can parse another document that declares an entity with the same
name. Both parses use the same `XmlState` entity
map on the librsvg side. `entity_insert()` replaces the first entry, whose `Drop`
implementation calls `xmlFreeNode()`. The outer `xmlCtxtParseEntity()`
then keeps using the freed 144-byte `xmlEntity`.

The included parse should not free an entity that the outer parser is still using.

The fix is in commit 8a1b0cd319e9af2d1e9cf878081dd77f227a0504, where
librsvg will no longer free xmlEntity pointers that libxml2 is still
using.

Comment 1 Fabio Valentini 2026-09-27 20:17:59 UTC
Already fixed
in https://bodhi.fedoraproject.org/updates/FEDORA-2026-1e23d80c94 for F45
and in https://bodhi.fedoraproject.org/updates/FEDORA-2026-d804dc1feb for Rawhide
and older releases are not affected according to the upstream bug.


Note You need to log in before you can comment on or make changes to this bug.