CVE-2021-3516

Source
https://cve.org/CVERecord?id=CVE-2021-3516
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3516.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-3516
Downstream
Related
Published
2021-06-01T14:15:10.373Z
Modified
2026-07-08T22:13:15.694337Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "9.0"
                },
                {
                    "last_affected": "9.0"
                }
            ],
            "source": "CPE_STRING",
            "vendor_product": "debian:debian_linux",
            "cpes": [
                "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
            ]
        },
        {
            "extracted_events": [
                {
                    "introduced": "33"
                },
                {
                    "last_affected": "33"
                },
                {
                    "introduced": "34"
                },
                {
                    "last_affected": "34"
                }
            ],
            "source": "CPE_STRING",
            "vendor_product": "fedoraproject:fedora",
            "cpes": [
                "cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*",
                "cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"
            ]
        },
        {
            "extracted_events": [
                {
                    "introduced": "8.8"
                },
                {
                    "last_affected": "8.8"
                }
            ],
            "source": "CPE_STRING",
            "vendor_product": "oracle:zfs_storage_appliance_kit",
            "cpes": [
                "cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*"
            ]
        },
        {
            "extracted_events": [
                {
                    "introduced": "7.0"
                },
                {
                    "last_affected": "7.0"
                },
                {
                    "introduced": "8.0"
                },
                {
                    "last_affected": "8.0"
                }
            ],
            "source": "CPE_STRING",
            "vendor_product": "redhat:enterprise_linux",
            "cpes": [
                "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*"
            ]
        }
    ]
}
References

Affected packages

Git / gitlab.gnome.org/gnome/libxml2

Affected ranges

Type
GIT
Repo
https://gitlab.gnome.org/gnome/libxml2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Last affected
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.9.11"
        },
        {
            "introduced": "6.0"
        },
        {
            "last_affected": "6.0"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING",
        "REFERENCES"
    ],
    "cpe": [
        "cpe:2.3:a:xmlsoft:xmllint:*:*:*:*:*:*:*:*",
        "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
    ]
}

Affected versions

6.*
6.0
Other
CVE-2013-2877
CVE-2014-0191
CVE-2014-3660
CVE-2015-1819
CVE-2015-5312
CVE-2015-7497
CVE-2015-7498
CVE-2015-7499-1
CVE-2015-7499-2
CVE-2015-7500
CVE-2015-7941_1
CVE-2015-7941_2
CVE-2015-7942
CVE-2015-7942-2
CVE-2015-8035
CVE-2015-8242
CVE-2015-8317
CVE-2016-1762
CVE-2016-1833
CVE-2016-1834
CVE-2016-1835
CVE-2016-1836
CVE-2016-1837
CVE-2016-1838
CVE-2016-1839
CVE-2016-1840
CVE-2016-3627
CVE-2016-3705
CVE-2016-4449
CVE-2016-4483
CVE-2021-3541
LIBXML2_2_6_1
LIBXML2_2_6_11
LIBXML2_2_6_12
LIBXML2_2_6_13
LIBXML2_2_6_14
LIBXML2_2_6_15
LIBXML2_2_6_16
LIBXML2_2_6_18
LIBXML2_2_6_19
LIBXML2_2_6_2
LIBXML2_2_6_20
LIBXML2_2_6_21
LIBXML2_2_6_22
LIBXML2_2_6_23
LIBXML2_2_6_24
LIBXML2_2_6_26
LIBXML2_2_6_27
LIBXML2_2_6_28
LIBXML2_2_6_3
LIBXML2_2_6_4
LIBXML2_2_6_5
LIBXML2_2_6_6
LIBXML2_2_6_7
LIBXML2_2_6_8
LIBXML2_2_6_9
LIBXML2_6_0
LIBXML_2_6_10
LIBXML2.*
LIBXML2.6.32
LIBXML2.7.0
LIBXML2.7.1
LIBXML2.7.2
LIBXML2.7.3
v2.*
v2.7.4
v2.7.5
v2.7.6
v2.7.7
v2.7.8
v2.8.0
v2.8.0-rc1
v2.8.0-rc2
v2.9.0
v2.9.0-rc2
v2.9.1
v2.9.10
v2.9.10-rc1
v2.9.2
v2.9.2-rc1
v2.9.2-rc2
v2.9.3
v2.9.4
v2.9.4-rc1
v2.9.4-rc2
v2.9.5
v2.9.5-rc1
v2.9.5-rc2
v2.9.6
v2.9.6-rc1
v2.9.7
v2.9.7-rc1
v2.9.8
v2.9.8-rc1
v2.9.9
v2.9.9-rc1
v2.9.9-rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3516.json"
vanir_signatures_modified
"2026-07-08T22:13:15Z"
vanir_signatures
[
    {
        "digest": {
            "line_hashes": [
                "125923364555687102912767750593616075062",
                "164402031157988608807981467698484062586",
                "187480151731575691958788539215601771876",
                "198926099027557728522349673134118447470"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2021-3516-22c624ac",
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://gitlab.gnome.org/gnome/libxml2@1358d157d0bd83be1dfe356a69213df9fac0b539",
        "signature_type": "Line",
        "target": {
            "file": "xmllint.c"
        }
    },
    {
        "digest": {
            "line_hashes": [
                "61551077790304056876126381115245055965",
                "278846916215258117913027984776762678417",
                "335982757857177150834168525661853921922",
                "87840030754328165737181167332541198940",
                "61551077790304056876126381115245055965",
                "278846916215258117913027984776762678417",
                "105711474186756975709469310745455797308",
                "103706706750952072917010335478765316004",
                "227047217400973127911964602216150042388",
                "253258039250536385915162828640596572926",
                "335982757857177150834168525661853921922",
                "87840030754328165737181167332541198940",
                "227047217400973127911964602216150042388",
                "253258039250536385915162828640596572926",
                "105711474186756975709469310745455797308",
                "263486003320329746243870951465374401173",
                "112950646771093583388072220651695062566",
                "231864520689178078662381811343978537663",
                "213333773092754020127207462965134162165",
                "19008729915787537273927561381864711242",
                "112950646771093583388072220651695062566",
                "231864520689178078662381811343978537663",
                "213333773092754020127207462965134162165",
                "19008729915787537273927561381864711242",
                "273240550832595461615251408636344817319",
                "162912241845094166163791832543701405088",
                "671650474723048413359612334217206008",
                "22766956053755843453510076977580137201",
                "13167474649499926961065524423099785312",
                "83470413458974766405520199037916535562",
                "276402490468899750538561900822383734744",
                "333682037389609673181412300351361172030",
                "9499193487410093391036358074880903632",
                "30805303948970631633603096678317204355",
                "93889085830397632709481663916004609330",
                "229956981014592868447519071218013779439",
                "240624245583924818381392266620352655927",
                "223174899253645334504338538819361168413",
                "294476493037697202535040764027097131119",
                "129304591418198192271541858825325701656",
                "140204848231080657012011575632498051783",
                "75311632195512841680531928924350830586",
                "256053888072821081238103619703165798762",
                "235378452580802392739918607691411522119",
                "244992818881073020881304797438692585130",
                "66651940352215863530508914348900210359",
                "48019944339009281467628355593178272818",
                "106918772490863171659640772695582053951",
                "116925370429586760959130651896312835976",
                "148133004854708868535797103792350393744",
                "102183146399774788380381559441867815797",
                "308117370035021215489377534456228663968",
                "187339639605561687559806077174150854909",
                "130836858511549172127312257489846408951",
                "52797561731550596294797782502825671297",
                "313419538420946173683294680071732735569",
                "246138447249870484217065672110268629284"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2021-3516-5d358667",
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://gitlab.gnome.org/gnome/libxml2@e1bcffea180d6cc0651757bb64284a763e0e2239",
        "signature_type": "Line",
        "target": {
            "file": "testapi.c"
        }
    },
    {
        "digest": {
            "function_hash": "198329610838053062539893085088781189951",
            "length": 1155.0
        },
        "id": "CVE-2021-3516-88b79f4c",
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://gitlab.gnome.org/gnome/libxml2@e1bcffea180d6cc0651757bb64284a763e0e2239",
        "signature_type": "Function",
        "target": {
            "function": "test_xmlIO",
            "file": "testapi.c"
        }
    }
]