libxml2 xmlcatalog buffer overflow patched
Stack-based buffer overflows in libxml2's xmlcatalog shell mode can cause crashes or enable code execution via malicious input.
CERT Polska coordinated disclosure of CVE-2026-11979, a vulnerability in the xmlsoft libxml2 library. The flaw affects the xmlcatalog utility when operating in shell mode, where the usershell() function processes user input using fixed-size stack buffers without proper bounds checking. An attacker can supply overly long input to overflow internal buffers (command, arg, and argv) during parsing, causing memory corruption within the stack frame.
Successful exploitation may result in application crashes or potentially allow arbitrary code execution within the xmlcatalog process context. The issue has been addressed in commit c2e233fc. The maintainers characterized this as a bug rather than a security vulnerability, though it received a CVE identifier through the coordinated disclosure process.
The vulnerability was reported by security researchers Michal Majchrowicz and Marcin Wyczechowski from AFINE and disclosed through CERT Polska's coordinated vulnerability disclosure program.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-11979/
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free