vulnerability

Red Hat: CVE-2021-3518: CVE-2021-3518 libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c (Multiple Advisories)

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
May 18, 2021
Added
Jun 30, 2021
Modified
Aug 11, 2025

Description

There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.

Solutions

no-fix-redhat-rpm-packageredhat-upgrade-libxml2redhat-upgrade-libxml2-debuginforedhat-upgrade-libxml2-debugsourceredhat-upgrade-libxml2-develredhat-upgrade-python3-libxml2redhat-upgrade-python3-libxml2-debuginfo
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.