CVE-2026-76781: Red Hat Enterprise Linux 10
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS).
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Hardened Images: before 2.15.3-0.1.3.hum1 (fixed in 2.15.3-0.1.3.hum1)
- Red Hat Red Hat Openshift Container Platform 4
Published 2026-09-17. Last modified 2026-09-24.