Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE 15-SP7 libxml2 Moderate Application Crash Issues SUSE-SU-2026-0605-1

suse
Calendar Grey February 24, 2026
Dist Suse Esm H88
This update addresses six issues in libxml2, fixing application crashes and resource consumption vulnerabilities.
An update that solves six vulnerabilities and has eight security fixes can now be installed.

Summary

## This update for libxml2 fixes the following issues: * CVE-2026-0990: Fixed a call stack overflow leading to application crash due to infinite recursion in `xmlCatalogXMLResolveURI`. (bsc#1256807, bsc#1256811) * CVE-2026-0992: Fixed an excessive resource consumption when processing XML catalogs due to exponential behavior. (bsc#1256809, bsc#1256812) * CVE-2026-1757: Fixed a memory leak in the `xmllint` interactive shell. (bsc#1257594, bsc#1257595) * CVE-2025-10911: Fixed a use-after-free with key data stored cross-RVT. (bsc#1250553) * CVE-2025-8732: Fixed an infinite recursion in catalog parsing functions when processing malformed SGML catalog files. (bsc#1247858) * CVE-2026-0989: Fixe a call stack exhaustion leading to application crash due

References

* bsc#1247850

* bsc#1247858

* bsc#1250553

* bsc#1256804

* bsc#1256805

* bsc#1256807

* bsc#1256808

* bsc#1256809

* bsc#1256810

* bsc#1256811

* bsc#1256812

* bsc#1257593

* bsc#1257594

* bsc#1257595

Cross-

* CVE-2025-10911

* CVE-2025-8732

* CVE-2026-0989

* CVE-2026-0990

* CVE-2026-0992

* CVE-2026-1757

CVSS scores:

* CVE-2025-10911 ( SUSE ): 6.8

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-10911 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2025-10911 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2025-8732 ( SUSE ): 4.8

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

* CVE-2025-8732 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

* CVE-2025-8732 ( NVD ): 1.9

Announcement ID: SUSE-SU-2026:0605-1
Release Date: 2026-02-24T11:19:21Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here