[Git][security-tracker-team/security-tracker][master] Track fixes for libxml2 via unstable upload
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 5 19:48:49 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
197f6222 by Salvatore Bonaccorso at 2026-09-05T20:48:22+02:00
Track fixes for libxml2 via unstable upload
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -20,31 +20,31 @@ CVE-2026-8623 (The Dear Flipbook \u2013 PDF Flipbook, 3D Flipbook, PDF embed, PD
CVE-2026-8447 (IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site ...)
NOT-FOR-US: IBM
CVE-2026-86144 (In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXInclu ...)
- - libxml2 <unfixed> (bug #1146744)
+ - libxml2 2.15.4+dfsg-1 (bug #1146744)
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/b63cd517afecb76582dd9488c55e54ceaf50de61 (v2.15.4)
CVE-2026-86143 (In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteC ...)
- - libxml2 <unfixed> (bug #1146744)
+ - libxml2 2.15.4+dfsg-1 (bug #1146744)
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/90f293ba74d28b1d570920382e707586f68ebf35 (v2.15.4)
CVE-2026-86142 (In libxml2 before 2.15.4, there is a heap-based buffer overflow in xml ...)
- - libxml2 <unfixed> (bug #1146744)
+ - libxml2 2.15.4+dfsg-1 (bug #1146744)
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1113
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/6b3a736c0edc74ceec3d82f5252499d7911b3a58 (v2.15.4)
CVE-2026-86141 (xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in x ...)
- - libxml2 <unfixed> (bug #1146744)
+ - libxml2 2.15.4+dfsg-1 (bug #1146744)
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1107
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/e89a8aae4c9b40cdafcf66b3f9e57c62db37bb55 (v2.15.4)
CVE-2026-86140 (In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat ...)
- - libxml2 <unfixed> (bug #1146744)
+ - libxml2 2.15.4+dfsg-1 (bug #1146744)
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/d1686f91dbda141a752200419d35639fd6b38340 (v2.15.4)
CVE-2026-86139 (In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer over ...)
- - libxml2 <unfixed> (bug #1146744)
+ - libxml2 2.15.4+dfsg-1 (bug #1146744)
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/8edbbdb09f24d26a2f900141fddc2b9d014f53b0 (v2.15.4)
CVE-2026-86138 (In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer o ...)
- - libxml2 <unfixed> (bug #1146744)
+ - libxml2 2.15.4+dfsg-1 (bug #1146744)
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4 (v2.15.4)
CVE-2026-86137 (In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds ...)
- - libxml2 <unfixed> (bug #1146744)
+ - libxml2 2.15.4+dfsg-1 (bug #1146744)
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1099
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/76fe08d97de88bfaef2f7d5cd27f11954cc5bee2 (v2.15.4)
CVE-2026-86100 (Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect ta ...)
@@ -71405,9 +71405,10 @@ CVE-2026-12672
CVE-2026-12616 (The /v1/upload/sbom endpoint extracts the iss claim from the attacker- ...)
NOT-FOR-US: Eclipse
CVE-2026-11979 (libxml2 is vulnerable to multiple stack-based buffer overflows in the ...)
- - libxml2 <unfixed> (unimportant)
+ - libxml2 2.15.4+dfsg-1 (unimportant)
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1124
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e
+ NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/commit/cd48d441f8fb1cf84e74c393310b72e4534de435 (v2.15.4)
NOTE: Not considered a security issue upstream
CVE-2026-11720 (A path traversal vulnerability exists in the HTTP tool URL builder of ...)
NOT-FOR-US: Google MCP Toolbox for Databases
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/197f622255a757f07d5b6a50fff9a4bb21c8f466
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/197f622255a757f07d5b6a50fff9a4bb21c8f466
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/9e96b246/attachment.htm>
More information about the debian-security-tracker-commits
mailing list