[From nobody Sat Sep  5 19:37:05 2026
Received: (at submit) by bugs.debian.org; 5 Sep 2026 09:18:50 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-9.9 required=4.0 tests=BAYES_00, FOURLA,
 FROMDEVELOPER, 
 NO_RELAYS,XMAILER_REPORTBUG autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 65; hammy, 150; neutral, 74; spammy,
 0. spammytokens: hammytokens:0.000-+--XDebbugsCc,
 0.000-+--X-Debbugs-Cc, 0.000-+--H*F:U*carnil, 0.000-+--H*Ad:N*Bug,
 0.000-+--HTo:N*Debian
Return-path: &lt;carnil@debian.org&gt;
Received: via submission by buxtehude.debian.org with esmtp (Exim 4.96)
 (envelope-from &lt;carnil@debian.org&gt;) id 1x2mXw-008R2L-0c
 for submit@bugs.debian.org; Sat, 05 Sep 2026 09:18:50 +0000
Content-Type: text/plain; charset=&quot;us-ascii&quot;
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Salvatore Bonaccorso &lt;carnil@debian.org&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: libxml2: CVE-2026-86137 CVE-2026-86138 CVE-2026-86139 CVE-2026-86140
 CVE-2026-86141 CVE-2026-86142 CVE-2026-86143 CVE-2026-86144
Message-ID: &lt;178859992725.1115859.8053215092100433715.reportbug@eldamar.lan&gt;
X-Mailer: reportbug 13.2.0+nmu1
Date: Sat, 05 Sep 2026 11:18:47 +0200
Delivered-To: submit@bugs.debian.org

Source: libxml2
Version: 2.15.3+dfsg-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team &lt;team@security.debian.org&gt;

Hi,

The following vulnerabilities were published for libxml2.

CVE-2026-86137[0]:
| In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-
| bounds read, aka an out-of-bounds read in the NXT macro in
| xmlregexp.


CVE-2026-86138[1]:
| In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer
| overflow and resultant heap-based buffer overflow.


CVE-2026-86139[2]:
| In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer
| overflow.


CVE-2026-86140[3]:
| In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a
| strcat stack-based buffer overflow.


CVE-2026-86141[4]:
| xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in
| xmlRegNewParserCtxt after a strdup failure, i.e., it does not
| calculate a string length after NULL checking.


CVE-2026-86142[5]:
| In libxml2 before 2.15.4, there is a heap-based buffer overflow in
| xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length
| saturation.


CVE-2026-86143[6]:
| In xmlIO in libxml2 before 2.15.4, an inconsistency in
| xmlOutputWriteCallback and xmlBufUse causes negative lengths to
| reach write callbacks, aka a lack of a check for integer overflow
| before calling writecallback. This has security relevance for many
| types of uses of that length value within a callback.


CVE-2026-86144[7]:
| In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and
| xmlXIncludeProcessTree do not propagate parseFlags. This has
| security relevance for, for example, the XML_PARSE_NONET flag, if
| (without it) a custom resource loader accesses the internet and
| triggers XML external entity injection, SSRF, or a denial of service
| (e.g., for an attacker-controlled internet resource that is
| intentionally slow).


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities &amp; Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-86137
    https://www.cve.org/CVERecord?id=CVE-2026-86137
[1] https://security-tracker.debian.org/tracker/CVE-2026-86138
    https://www.cve.org/CVERecord?id=CVE-2026-86138
[2] https://security-tracker.debian.org/tracker/CVE-2026-86139
    https://www.cve.org/CVERecord?id=CVE-2026-86139
[3] https://security-tracker.debian.org/tracker/CVE-2026-86140
    https://www.cve.org/CVERecord?id=CVE-2026-86140
[4] https://security-tracker.debian.org/tracker/CVE-2026-86141
    https://www.cve.org/CVERecord?id=CVE-2026-86141
[5] https://security-tracker.debian.org/tracker/CVE-2026-86142
    https://www.cve.org/CVERecord?id=CVE-2026-86142
[6] https://security-tracker.debian.org/tracker/CVE-2026-86143
    https://www.cve.org/CVERecord?id=CVE-2026-86143
[7] https://security-tracker.debian.org/tracker/CVE-2026-86144
    https://www.cve.org/CVERecord?id=CVE-2026-86144

Regards,
Salvatore
]