AI analysis
A NULL pointer dereference (CWE-476) in libxml2 is triggered when an XML catalog contains a nextCatalog element that omits its mandatory catalog attribute. A local user, or an attacker who can supply a specially crafted XML catalog, can crash the application during catalog parsing and cause a denial of service. Impact is limited to availability: CVSS 3.1 is 5.5 (medium), with a local attack vector, no privileges required, and user interaction required. The library is widely packaged, including by Red Hat (the assigning CNA) and Ubuntu (USN-8910-1), so any system or application that parses XML catalogs may be affected. No public proof of concept is known and the flaw is not in the CISA KEV catalog.
What to do: Install the libxml2 update from your operating-system or application vendor as soon as it is available (Ubuntu tracks this in USN-8910-1; Red Hat is the CNA and other distributors should ship corresponding packages). Until patched builds are in place, do not process untrusted or user-supplied XML catalogs, and restrict who can provide catalog files to applications that load them.
Affected
| libxml2 project (GNOME/xmlsoft; packaged by distributors including Red Hat and U libxml2 | — |
Estimated exposure
massHundreds of millions of systems ship libxml2; far fewer are exposed unless they parse attacker-supplied XML catalogs — libxml2 is a foundational XML library shipped by essentially all major Linux distributions and many other platforms and applications; Red Hat assigned the CVE and Ubuntu published USN-8910-1, but no install count is in the data, so this is…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS).