Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE 2026-0606-1 libxml2 Moderate Resource Leak App Crash Fix

suse
Calendar Grey February 24, 2026
Dist Suse Esm H88
Update addresses five vulnerabilities for libxml2 on SUSE systems, improves security with multiple fixes for better stability.
An update that solves five vulnerabilities and has seven security fixes can now be installed.

Summary

## This update for libxml2 fixes the following issues: * CVE-2026-0990: Fixed a call stack overflow leading to application crash due to infinite recursion in `xmlCatalogXMLResolveURI`. (bsc#1256807, bsc#1256811) * CVE-2026-0992: Fixed an excessive resource consumption when processing XML catalogs due to exponential behavior. (bsc#1256809, bsc#1256812) * CVE-2026-1757: Fixed a memory leak in the `xmllint` interactive shell. (bsc#1257594, bsc#1257595) * CVE-2025-10911: Fixed a use-after-free with key data stored cross-RVT. (bsc#1250553) * CVE-2026-0989: Fixe a call stack exhaustion leading to application crash due to RelaxNG parser not limiting the recursion depth. (bsc#1256805, bsc#1256810) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like

References

* bsc#1250553

* bsc#1256804

* bsc#1256805

* bsc#1256807

* bsc#1256808

* bsc#1256809

* bsc#1256810

* bsc#1256811

* bsc#1256812

* bsc#1257593

* bsc#1257594

* bsc#1257595

Cross-

* CVE-2025-10911

* CVE-2026-0989

* CVE-2026-0990

* CVE-2026-0992

* CVE-2026-1757

CVSS scores:

* CVE-2025-10911 ( SUSE ): 6.8

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-10911 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2025-10911 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2026-0989 ( SUSE ): 6.3

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

* CVE-2026-0989 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2026-0989 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Announcement ID: SUSE-SU-2026:0606-1
Release Date: 2026-02-24T11:19:39Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here