[xml/sgml-pkgs] Bug#1146744: libxml2: CVE-2026-86137 CVE-2026-86138 CVE-2026-86139 CVE-2026-86140 CVE-2026-86141 CVE-2026-86142 CVE-2026-86143 CVE-2026-86144
Salvatore Bonaccorso
carnil at debian.org
Sat Sep 5 10:18:47 BST 2026
Source: libxml2
Version: 2.15.3+dfsg-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Hi,
The following vulnerabilities were published for libxml2.
CVE-2026-86137[0]:
| In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-
| bounds read, aka an out-of-bounds read in the NXT macro in
| xmlregexp.
CVE-2026-86138[1]:
| In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer
| overflow and resultant heap-based buffer overflow.
CVE-2026-86139[2]:
| In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer
| overflow.
CVE-2026-86140[3]:
| In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a
| strcat stack-based buffer overflow.
CVE-2026-86141[4]:
| xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in
| xmlRegNewParserCtxt after a strdup failure, i.e., it does not
| calculate a string length after NULL checking.
CVE-2026-86142[5]:
| In libxml2 before 2.15.4, there is a heap-based buffer overflow in
| xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length
| saturation.
CVE-2026-86143[6]:
| In xmlIO in libxml2 before 2.15.4, an inconsistency in
| xmlOutputWriteCallback and xmlBufUse causes negative lengths to
| reach write callbacks, aka a lack of a check for integer overflow
| before calling writecallback. This has security relevance for many
| types of uses of that length value within a callback.
CVE-2026-86144[7]:
| In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and
| xmlXIncludeProcessTree do not propagate parseFlags. This has
| security relevance for, for example, the XML_PARSE_NONET flag, if
| (without it) a custom resource loader accesses the internet and
| triggers XML external entity injection, SSRF, or a denial of service
| (e.g., for an attacker-controlled internet resource that is
| intentionally slow).
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-86137
https://www.cve.org/CVERecord?id=CVE-2026-86137
[1] https://security-tracker.debian.org/tracker/CVE-2026-86138
https://www.cve.org/CVERecord?id=CVE-2026-86138
[2] https://security-tracker.debian.org/tracker/CVE-2026-86139
https://www.cve.org/CVERecord?id=CVE-2026-86139
[3] https://security-tracker.debian.org/tracker/CVE-2026-86140
https://www.cve.org/CVERecord?id=CVE-2026-86140
[4] https://security-tracker.debian.org/tracker/CVE-2026-86141
https://www.cve.org/CVERecord?id=CVE-2026-86141
[5] https://security-tracker.debian.org/tracker/CVE-2026-86142
https://www.cve.org/CVERecord?id=CVE-2026-86142
[6] https://security-tracker.debian.org/tracker/CVE-2026-86143
https://www.cve.org/CVERecord?id=CVE-2026-86143
[7] https://security-tracker.debian.org/tracker/CVE-2026-86144
https://www.cve.org/CVERecord?id=CVE-2026-86144
Regards,
Salvatore
More information about the debian-xml-sgml-pkgs
mailing list