DEBIAN-CVE-2026-1757

Source
https://security-tracker.debian.org/tracker/CVE-2026-1757
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-1757.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-1757
Upstream
Published
2026-02-02T13:15:58Z
Modified
2026-09-14T17:02:32Z
Severity
  • 6.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.

References

Affected packages

Debian:12 / libxml2

Package

Name
libxml2
Purl
pkg:deb/debian/libxml2?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.9.14+dfsg-1.3~deb12u6

Affected versions

2.*
2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
2.9.14+dfsg-1.3~deb12u3
2.9.14+dfsg-1.3~deb12u4
2.9.14+dfsg-1.3~deb12u5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-1757.json"

Debian:13 / libxml2

Package

Name
libxml2
Purl
pkg:deb/debian/libxml2?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.12.7+dfsg+really2.9.14-2.1+deb13u3

Affected versions

2.*
2.12.7+dfsg+really2.9.14-2.1
2.12.7+dfsg+really2.9.14-2.1+deb13u1
2.12.7+dfsg+really2.9.14-2.1+deb13u2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-1757.json"

Debian:14 / libxml2

Package

Name
libxml2
Purl
pkg:deb/debian/libxml2?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.15.2+dfsg-0.1

Affected versions

2.*
2.12.7+dfsg+really2.9.14-2.1
2.13.1+dfsg-0exp1
2.13.3+dfsg-0exp1
2.13.3+dfsg-0exp2
2.14.1+dfsg-0exp1
2.14.2+dfsg-0exp1
2.14.3+dfsg-0exp1
2.14.3+dfsg-0exp2
2.14.3+dfsg-0exp3
2.14.4+dfsg-0exp1
2.14.5+dfsg-0exp1
2.14.5+dfsg-0exp2
2.14.5+dfsg-0.1
2.14.5+dfsg-0.2
2.14.6+dfsg-0.1
2.15.0+dfsg-0.1
2.15.0+dfsg-0.2
2.15.0+dfsg-0.3
2.15.1+dfsg-0.1
2.15.1+dfsg-0.2
2.15.1+dfsg-0.3
2.15.1+dfsg-0.4
2.15.1+dfsg-0.5
2.15.1+dfsg-1
2.15.1+dfsg-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-1757.json"