Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 2.3%top 18%

Red Hat Security Advisory: Red Hat Update Infrastructure 5.2 security update

0
High
Published: 07/23/2026 (07/23/2026, 13:13:25 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

CVE-2024-34459 is a buffer over-read vulnerability in the xmllint program distributed by the libxml2 package, specifically triggered when processing crafted files with the --htmlout option. This flaw can cause the application to crash, resulting in a denial of service. The issue only affects xmllint when the --htmlout command line option is used, and applications not using or exposing xmllint are not vulnerable. No fix is currently provided in the Red Hat advisory, and the vendor recommends avoiding processing untrusted files with xmllint as a mitigation.

Affected software

redhat/libxml2
pkg:rpm/redhat/libxml2
Affected versions
=2.9.7-13.el8_6.14

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/06/2026, 20:00:53 UTC

Technical Analysis

A buffer over-read vulnerability (CWE-126) exists in the xmllint program of the libxml2 package, specifically in the xmlHTMLPrintFileContext function. When xmllint processes a crafted file using the --htmlout command line option, it may read beyond the intended memory buffer, causing a crash and denial of service. The issue is local and requires user interaction to trigger. The vulnerability does not affect xmllint if the --htmlout option is not used, and applications not using or exposing xmllint are not vulnerable. Red Hat's advisory highlights the risk of denial of service and notes the absence of a current fix, recommending mitigation by avoiding processing untrusted files with xmllint.

Potential Impact

The vulnerability can cause xmllint to crash, resulting in denial of service when processing crafted files with the --htmlout option. There is no confidentiality or integrity impact reported. The flaw is local and requires user interaction. No known exploits are reported in the wild. The impact is limited to applications that use or expose the vulnerable xmllint program with the --htmlout option.

Mitigation Recommendations

Red Hat advises not to process untrusted files with the xmllint program using the --htmlout option. No official fix or patch is currently available according to the vendor advisory. Users should avoid using the vulnerable functionality on untrusted input to mitigate the risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:27737
Cve Count
1
Additional Cves
[]
Cvss Version
null

Threat ID: 6a395a05eed863c81e08e789

Added to database: 06/22/2026, 15:51:33 UTC

Last enriched: 08/06/2026, 20:00:53 UTC

Last updated: 08/07/2026, 00:41:05 UTC

Views: 119

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:44481https://access.redhat.com/products/red-hat-update-infrastructurehttps://access.redhat.com/security/cve/CVE-2024-34459https://access.redhat.com/security/cve/CVE-2025-10911https://access.redhat.com/security/cve/CVE-2025-13151https://access.redhat.com/security/cve/CVE-2025-5278https://access.redhat.com/security/cve/CVE-2025-6170https://access.redhat.com/security/cve/CVE-2026-15308https://access.redhat.com/security/cve/CVE-2026-31790https://access.redhat.com/security/cve/CVE-2026-41411https://access.redhat.com/security/cve/CVE-2026-42055https://access.redhat.com/security/cve/CVE-2026-44431https://access.redhat.com/security/cve/CVE-2026-44432https://access.redhat.com/security/cve/CVE-2026-48864https://access.redhat.com/security/cve/CVE-2026-5435https://access.redhat.com/security/cve/CVE-2026-54369https://access.redhat.com/security/cve/CVE-2026-54370https://access.redhat.com/security/cve/CVE-2026-5450https://access.redhat.com/security/cve/CVE-2026-58016https://access.redhat.com/security/cve/CVE-2026-5928https://access.redhat.com/errata/RHSA-2026:33313https://access.redhat.com/security/cve/CVE-2025-71319https://access.redhat.com/security/cve/CVE-2026-33416https://access.redhat.com/security/cve/CVE-2026-33636https://access.redhat.com/security/cve/CVE-2026-8643https://access.redhat.com/security/cve/CVE-2026-9256https://access.redhat.com/security/updates/classification/https://docs.redhat.com/en/documentation/subscription_central/1-latest/#DiscoveryCanonical URLhttps://access.redhat.com/errata/RHSA-2026:34102https://access.redhat.com/security/cve/CVE-2026-34180https://access.redhat.com/security/cve/CVE-2026-34181https://access.redhat.com/security/cve/CVE-2026-34182https://access.redhat.com/security/cve/CVE-2026-34183https://access.redhat.com/security/cve/CVE-2026-35177https://access.redhat.com/security/cve/CVE-2026-42764https://access.redhat.com/security/cve/CVE-2026-42766https://access.redhat.com/security/cve/CVE-2026-42767https://access.redhat.com/security/cve/CVE-2026-42768https://access.redhat.com/security/cve/CVE-2026-42769https://access.redhat.com/security/cve/CVE-2026-42770https://access.redhat.com/security/cve/CVE-2026-45445https://access.redhat.com/security/cve/CVE-2026-45446https://access.redhat.com/security/cve/CVE-2026-45447https://access.redhat.com/errata/RHSA-2026:26354https://access.redhat.com/security/updates/classification/#low2280532Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses