Bug 2539279 (CVE-2026-96889, RUSTSEC-2026-0305) - CVE-2026-96889 librsvg: Use-after-free when XML includes have duplicated entities
Summary: CVE-2026-96889 librsvg: Use-after-free when XML includes have duplicated enti...
Keywords:
Status: NEW
Alias: CVE-2026-96889, RUSTSEC-2026-0305
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2539674 2539673 2539685
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-23 09:29 UTC by OSIDB Bzimport
Modified: 2026-09-30 02:09 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-23 09:29:37 UTC
Librsvg uses libxml2, a C library, to parse XML.  When librsvg parses
an SVG document which has a nested Xinclude, an XML entity declaration
with a duplicate name as an existing one can cause a use-after-free error.

While libxml2 is expanding an internal entity, a recursive XInclude
can parse another document that declares an entity with the same
name. Both parses use the same `XmlState` entity
map on the librsvg side. `entity_insert()` replaces the first entry, whose `Drop`
implementation calls `xmlFreeNode()`. The outer `xmlCtxtParseEntity()`
then keeps using the freed 144-byte `xmlEntity`.

The included parse should not free an entity that the outer parser is still using.

The fix is in commit 8a1b0cd319e9af2d1e9cf878081dd77f227a0504, where
librsvg will no longer free xmlEntity pointers that libxml2 is still
using.

Comment 2 Akiyoshi Kurita 2026-09-30 02:09:55 UTC
A public proof-of-concept for CVE-2026-96889 has been released:

https://github.com/rafabd1/VectorFreed

Red Hat CVE page:
https://access.redhat.com/security/cve/cve-2026-96889

The published PoC reproduces the librsvg use-after-free involving nested XInclude processing and duplicate XML entity declarations.

The researcher also states that command execution has been achieved in multiple downstream application paths, although a universal end-to-end RCE PoC is not currently public.

Since a working UAF PoC is now publicly available, could Red Hat Product Security please re-evaluate the impact and remediation priority for affected RHEL packages?

In particular, please confirm whether:

- affected RHEL packages reproduce the issue with the public PoC;
- exploitation may lead to arbitrary code execution when attacker-controlled SVG content is processed;
- security updates are planned for affected RHEL releases.


Note You need to log in before you can comment on or make changes to this bug.