CVE-2026-76781: Red Hat Enterprise Linux 10

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS).

Affected products

  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Hardened Images: before 2.15.3-0.1.3.hum1 (fixed in 2.15.3-0.1.3.hum1)
  • Red Hat Red Hat Openshift Container Platform 4

Published 2026-09-17. Last modified 2026-09-24.