AZL-100941

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100941.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-100941
Upstream
  • CVE-2026-74860
Published
2026-09-08T12:16:58Z
Modified
2026-09-16T06:39:01Z
Summary
CVE-2026-74860 affecting package libxml2 2.11.5-10
Details

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.

References

Affected packages

Azure Linux:3 / libxml2

Package

Name
libxml2
Purl
pkg:rpm/azure-linux/libxml2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.11.5-10

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100941.json"