AZL-104931

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104931.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-104931
Upstream
  • CVE-2026-96889
Published
2026-09-23T20:17:27Z
Modified
2026-09-27T14:16:20Z
Summary
CVE-2026-96889 affecting package librsvg2 2.58.1-8
Details

A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.

References

Affected packages

Azure Linux:3 / librsvg2

Package

Name
librsvg2
Purl
pkg:rpm/azure-linux/librsvg2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.58.1-8

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104931.json"