Vulnerability RUSTSEC-2026-0305

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
5 days ago
September 23, 2026 at 12:00 PM UTC
Use-after-free when XML includes have duplicated entities
2.56.0 - 2.56.92 and 2.57.0 - 2.57.3 and 2.58.0 - 2.58.5 and 2.59.0 - 2.59.2 and 2.60.0 - 2.60.2
2.56.0 - 2.56.92 and 2.57.0 - 2.57.3 and 2.58.0 - 2.58.5 and 2.59.0 - 2.59.2 and 2.60.0 - 2.60.2

Summary

Use-after-free when XML includes have duplicated entities

Details

Librsvg uses libxml2, a C library, to parse XML. When librsvg parses an SVG document which has a nested Xinclude, an XML entity declaration with a duplicate name as an existing one can cause a use-after-free error.

While libxml2 is expanding an internal entity, a recursive XInclude can parse another document that declares an entity with the same name. Both parses use the same XmlState entity map on the librsvg side. entity_insert() replaces the first entry, whose Drop implementation calls xmlFreeNode(). The outer xmlCtxtParseEntity() then keeps using the freed 144-byte xmlEntity.

The included parse should not free an entity that the outer parser is still using.

The fix is in commit 8a1b0cd319e9af2d1e9cf878081dd77f227a0504, where librsvg will no longer free xmlEntity pointers that libxml2 is still using.

Impacted packages

Timeline

Published
5 days ago
September 23, 2026 at 12:00 PM UTC
Fixed (2.63.2)
10 days ago
September 18, 2026 at 11:40 PM UTC
Fixed (2.62.4)
7 days ago
September 22, 2026 at 02:18 AM UTC
Fixed (2.61.5)
3 days ago
September 25, 2026 at 09:33 PM UTC
Fixed (2.60.3)
12 hours ago
September 28, 2026 at 09:50 PM UTC
Last Modified
4 hours ago
September 29, 2026 at 05:15 AM UTC