CVE-2026-74860: Release of Invalid Pointer or Reference in Red Hat Red Hat Enterprise Linux 10
A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.
AI Analysis
Technical Summary
This vulnerability in libxml2's Python bindings arises from a double-free error in the SAX attributeDecl callback handler when processing a crafted XML document with a DTD containing enumerated attribute values. The double-free occurs because a string is freed twice, leading to memory corruption and a reproducible crash. The flaw can be exploited remotely by an attacker providing malicious XML input, resulting in denial of service in Python applications that use libxml2 SAX bindings. The CVSS v3.1 score is 8.5, reflecting high impact on confidentiality, integrity, and availability, with network attack vector, high attack complexity, low privileges required, and no user interaction needed. Red Hat is the authoritative source for this vulnerability affecting Red Hat Enterprise Linux 10, but no official fix or patch has been confirmed yet.
Potential Impact
The vulnerability allows a remote attacker to cause a denial of service by crashing Python applications that use libxml2 SAX bindings through a crafted XML input. The flaw impacts confidentiality, integrity, and availability due to memory corruption from a double-free error. There are no known exploits in the wild at this time. The attack requires low privileges but has high attack complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-74860 for current remediation guidance. No official fix or patch has been announced as of the latest advisory. Users should monitor the vendor advisory for updates. No specific mitigations are provided by Red Hat at this time.
CVE-2026-74860: Release of Invalid Pointer or Reference in Red Hat Red Hat Enterprise Linux 10
Description
A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.
CVSS v3.1
Score 8.5high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in libxml2's Python bindings arises from a double-free error in the SAX attributeDecl callback handler when processing a crafted XML document with a DTD containing enumerated attribute values. The double-free occurs because a string is freed twice, leading to memory corruption and a reproducible crash. The flaw can be exploited remotely by an attacker providing malicious XML input, resulting in denial of service in Python applications that use libxml2 SAX bindings. The CVSS v3.1 score is 8.5, reflecting high impact on confidentiality, integrity, and availability, with network attack vector, high attack complexity, low privileges required, and no user interaction needed. Red Hat is the authoritative source for this vulnerability affecting Red Hat Enterprise Linux 10, but no official fix or patch has been confirmed yet.
Potential Impact
The vulnerability allows a remote attacker to cause a denial of service by crashing Python applications that use libxml2 SAX bindings through a crafted XML input. The flaw impacts confidentiality, integrity, and availability due to memory corruption from a double-free error. There are no known exploits in the wild at this time. The attack requires low privileges but has high attack complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-74860 for current remediation guidance. No official fix or patch has been announced as of the latest advisory. Users should monitor the vendor advisory for updates. No specific mitigations are provided by Red Hat at this time.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-08-17T09:57:05.862Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-74860","vendor":"Red Hat"}]
Threat ID: 6a9ff394acd9273b49949e2c
Added to database: 09/08/2026, 11:37:56 UTC
Last enriched: 09/08/2026, 11:53:01 UTC
Last updated: 09/09/2026, 01:17:53 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.