Logo
vulnerabilityCVE-2026-1757
Name
CVE-2026-1757
Source
NVD ( link)Debian ( link)
Description
A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
libxml2
Patched

Vulnerability Ratings#


6.2
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.15.3
Not Affected
buildroot
master
2.15.3
Not Affected
openwrt
master
2.15.3-r1
Not Affected
openwrt
openwrt-25.12
2.15.1-r1
Not Affected
yocto
kirkstone
2.9.14
Not Affected
yocto
master
2.15.3
Not Affected

Resolved with patches#


libxml2 (yocto:scarthgap)

#
Title
Author
Resolve
1
shell: free cmdline before continue
Mingli Yu <mingli.yu@windriver.com>
CVE-2026-1757