CVE-2026-0990Patch(ibm / aix)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ibm aix systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aix
  • enterprise_linux
  • hardened_images
  • jboss_core_services

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-02-18); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
aixenterprise_linuxhardened_imagesjboss_core_serviceslibxml2openshift_container_platformvios

9 versions affected across 7 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-18: 1Mentions · 2026-02-23: 1Patch / Workaround · 2026-02-18: 1Technical Details · 2026-02-18: 102-1802-23
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-0990 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/403 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    CVE-2026-0990 has been removed from the latest AWS Lambda base images, indicating the vulnerability is no longer present in the environment.

    0000037
    30 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 #LinuxAdvisory: #SUSE releases critical libxml2 update (2026-0570-1). Patches 5 high-impact CVEs including infinite recursion (CVE-2026-0990) and memory corruption (CVE-2025-10911). Affects: openSUSE Leap 15.5/15.6 & SLE Micro 5.5. Read more: 👉 https://tinyurl.com/24xa4dky https://t.co/xrYrM4sXHr

    Post summary

    SUSE released a critical libxml2 update that patches five high‑impact CVEs, including CVE‑2026‑0990 (infinite recursion) and CVE‑2025‑10911 (memory corruption).

    0000046
    1.3K followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
OSibmaix---
OSibmaix7.3.4--
Appibmvios---
Appibmvios4.1.2.0--
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
Appredhathardened_images---
Appredhatjboss_core_services---
Appredhatopenshift_container_platform4.0--
Appxmlsoftlibxml2---

Explore more