Librsvg: use-after-free when xml includes have duplicated entities
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7.8epss 0.1%
from disclosure to weapon0 days
Published on NVDSep 23
1st PoCSep 21
exploitation probability
0.1%top 98% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Red Hat · Red Hat Enterprise Linux 10Red Hat · Red Hat Enterprise Linux 6Red Hat · Red Hat Enterprise Linux 7Red Hat · Red Hat Enterprise Linux 8Red Hat · Red Hat Enterprise Linux 9public PoCs found — 1
githubgithub.com/rafabd1/VectorFreed★ 9⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.