RHSA-2026:7519HighCVSS 9.1

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
April 10, 2026
Last Modified
September 5, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2025-6021 — libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 CVE-2025-6170 — libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling CVE-2025-9714 — libxslt: libxml2: Inifinite recursion at exsltDynMapFunction function in libexslt/dynamic.c CVE-2025-26434 — libxml2: Libxml2 out of bounds read CVE-2025-32414 — libxml2: Out-of-Bounds Read in libxml2 CVE-2025-32415 — libxml2: Out-of-bounds Read in xmlSchemaIDCFillNodeTables CVE-2025-49794 — libxml: Heap use after free (UAF) leads to Denial of service (DoS) CVE-2025-49795 — libxml: Null pointer dereference leads to Denial of service (DoS) CVE-2025-49796 — libxml: Type confusion leads to Denial of service (DoS) CVE-2026-0989 — libxml2: Unbounded RelaxNG Include Recursion Leading to Stack Overflow CVE-2026-0990 — libxml2: libxml2: Denial of Service via uncontrolled recursion in XML catalog processing CVE-2026-0992 — libxml2: libxml2: Denial of Service via crafted XML catalogs CVE-2026-1757 — libxml2: Memory Leak Leading to Local Denial of Service in xmllint Interactive Shell

🎯 Affected products4

  • Red Hat Hardened Images
  • libxml2-main@aarch64 as a component of Red Hat Hardened Images
  • libxml2-main@src as a component of Red Hat Hardened Images
  • libxml2-main@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Users are strongly advised to apply vendor-supplied patches as soon as they become available to address the underlying integer overflow flaw in the affected code. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to a widespread installation base, or stability. It is strongly recommended to apply the upstream patch once available. Workaround: The impact of this flaw may be reduced by setting strict resource limits to the stack size of processes at the operational system level. This can be achieved either through the 'ulimit' shell built-in or the 'limits.conf' file. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Do not process untrusted files with the libxml2 library. Workaround: There's no available mitigation other than avoid processing untrusted XML documents before updating to the libxml version containing the fix. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability. Workaround: There's no available mitigation other than to avoid processing untrusted XML documents if the user is unable/unwilling to update the library. Workaround: To mitigate this issue, restrict applications using libxml2 from processing untrusted RelaxNG schema files. Implement strict input validation and sanitization for all RelaxNG schema inputs to prevent the parsing of maliciously crafted, deeply nested include directives. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (17)