cbcvebase.
CVE-2021-3516
published 2021-06-01

CVE-2021-3516: There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a…

PriorityP343high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.99%
78.5th percentile
There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability.

Affected

18 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibxml2< libxml2 2.9.10+dfsg-6.6 (bookworm)libxml2 2.9.10+dfsg-6.6 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
nokogirinokogiri>= 0 < 1.11.41.11.4
oraclezfs_storage_appliance_kit
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.62.9.10+dfsg-6.6
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.62.9.10+dfsg-6.6
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.62.9.10+dfsg-6.6
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.62.9.10+dfsg-6.6
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-6.1ubuntu1.42.9.4+dfsg1-6.1ubuntu1.4
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-5ubuntu0.20.04.12.9.10+dfsg-5ubuntu0.20.04.1
xmlsoftlibxml2>= 0 < 2.9.1+dfsg1-3ubuntu4.13+esm22.9.1+dfsg1-3ubuntu4.13+esm2
xmlsoftlibxml2>= 0 < 2.9.3+dfsg1-1ubuntu0.7+esm12.9.3+dfsg1-1ubuntu0.7+esm1
xmlsoftxmllint< 2.9.112.9.11

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa7.5HIGH
osv9.1CRITICAL
vendor_ubuntu9.1CRITICAL
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.