Status: UPDATED
| Advisory ID: CVE-2026-96889
Key Details
| CVE | CVE-2026-96889 |
| CVSS Score / Version | 7.8 (High) / CVSS v3.1 |
| Updated | 2026-09-25 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Red Hat Red Hat Enterprise Linux 10, Red Hat Red Hat Enterprise Linux 8, Red Hat Red Hat Enterprise Linux 9, and Red Hat Red Hat Enterprise Linux 7 |
| Classified as | CWE-416 (Use After Free) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code. (NVD)
What to Do
Monitor Red Hat's web page for any future patch releases.
References