# libxml2 xmlcatalog buffer overflow patched

Published: 2026-06-29 · Severity: medium
Canonical: https://vorant.io/reports/1d4b6d14-5d22-5a32-ae32-fd1ae8e0bb76/libxml2-xmlcatalog-buffer-overflow-patched

> Stack-based buffer overflows in libxml2's xmlcatalog shell mode can cause crashes or enable code execution via malicious input.

CERT Polska coordinated disclosure of CVE-2026-11979, a vulnerability in the xmlsoft libxml2 library. The flaw affects the xmlcatalog utility when operating in shell mode, where the usershell() function processes user input using fixed-size stack buffers without proper bounds checking. An attacker can supply overly long input to overflow internal buffers (command, arg, and argv) during parsing, causing memory corruption within the stack frame.

Successful exploitation may result in application crashes or potentially allow arbitrary code execution within the xmlcatalog process context. The issue has been addressed in commit c2e233fc. The maintainers characterized this as a bug rather than a security vulnerability, though it received a CVE identifier through the coordinated disclosure process.

The vulnerability was reported by security researchers Michal Majchrowicz and Marcin Wyczechowski from AFINE and disclosed through CERT Polska's coordinated vulnerability disclosure program.

## Mentioned in this report

- Vulnerabilities: CVE-2026-11979

Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-11979/

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1d4b6d14-5d22-5a32-ae32-fd1ae8e0bb76/libxml2-xmlcatalog-buffer-overflow-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
