[Git][security-tracker-team/security-tracker][master] Add new batch of CVEs for libxml2

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 5 08:38:50 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
26a56add by Salvatore Bonaccorso at 2026-09-05T09:38:24+02:00
Add new batch of CVEs for libxml2

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11,21 +11,33 @@ CVE-2026-8623 (The Dear Flipbook \u2013 PDF Flipbook, 3D Flipbook, PDF embed, PD
 CVE-2026-8447 (IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site  ...)
 	NOT-FOR-US: IBM
 CVE-2026-86144 (In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXInclu ...)
-	TODO: check
+	- libxml2 <unfixed>
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/b63cd517afecb76582dd9488c55e54ceaf50de61 (v2.15.4)
 CVE-2026-86143 (In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteC ...)
-	TODO: check
+	- libxml2 <unfixed>
+	NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/90f293ba74d28b1d570920382e707586f68ebf35 (v2.15.4)
 CVE-2026-86142 (In libxml2 before 2.15.4, there is a heap-based buffer overflow in xml ...)
-	TODO: check
+	- libxml2 <unfixed>
+	NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1113
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/6b3a736c0edc74ceec3d82f5252499d7911b3a58 (v2.15.4)
 CVE-2026-86141 (xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in x ...)
-	TODO: check
+	- libxml2 <unfixed>
+	NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1107
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/e89a8aae4c9b40cdafcf66b3f9e57c62db37bb55 (v2.15.4)
 CVE-2026-86140 (In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat  ...)
-	TODO: check
+	- libxml2 <unfixed>
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/d1686f91dbda141a752200419d35639fd6b38340 (v2.15.4)
 CVE-2026-86139 (In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer over ...)
-	TODO: check
+	- libxml2 <unfixed>
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/8edbbdb09f24d26a2f900141fddc2b9d014f53b0 (v2.15.4)
 CVE-2026-86138 (In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer o ...)
-	TODO: check
+	- libxml2 <unfixed>
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4 (v2.15.4)
 CVE-2026-86137 (In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds  ...)
-	TODO: check
+	- libxml2 <unfixed>
+	NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1099
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/76fe08d97de88bfaef2f7d5cd27f11954cc5bee2 (v2.15.4)
 CVE-2026-86100 (Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect ta ...)
 	TODO: check
 CVE-2026-86098 (ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerabi ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/26a56add278af19f76e63ddec69a3a81f3141954

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/26a56add278af19f76e63ddec69a3a81f3141954
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/0be61751/attachment.htm>


More information about the debian-security-tracker-commits mailing list