ZeroHour
Vendor

libxml2

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Re: Vulnerabilities fixed in libxml2-2.15.4

libxml2 2.15.4 patches two flaws including a heap buffer overflow in xmlDictAddQString tracked as CVE-2026-86137 and CVE-2026-86138.

libxml2 releases before 2.15.4 are affected by an integer overflow in xmlDictAddQString in dict.c that leads to a heap-based buffer overflow, tracked as CVE-2026-86137 and CVE-2026-86138. The oss-security post from Debian's Salvatore Bonaccorso flags the fixed release for downstream tracking. No exploitation is mentioned in the disclosure.

Related CVEs

  • Heap Buffer Overflow via Integer Overflow in libxml2 before 2.15.4
    CVE-2026-86138 is an integer overflow (CWE-190) in xmlDictAddQString in dict.c of libxml2, the widely used XML parsing library; the miscalculated size calculation leads to a heap-based buffer overflow. It is triggered when an application built on an affected libxml2 processes crafted XML (or other structured input) that exercises the library's qualified-string dictionary handling in a way that makes a computed length wrap around, producing an undersized allocation and an out-of-bounds heap write; the CVSS vector (AV:L/AC:H) indicates the attack path requires local access or locally processed crafted input and that exploitation conditions are narrow. An attacker who triggers the bug gains heap memory corruption with the privileges of the affected process, with high confidentiality and integrity impact and low availability impact per the CVSS score, ranging from crashes to potentially limited code execution. Anyone deploying or embedding libxml2 versions before 2.15.4 is affected, which spans a very large share of Linux/Unix systems, language runtimes, and applications that parse XML. There is currently no public proof-of-concept, no CISA KEV listing, and a 0.1% EPSS score, indicating no known exploitation.
    · libxml2 (upstream project) libxml2 all versions prior to 2.15.4 (fixed in 2.15.4)mass
  • Out-of-bounds read in libxml2 XML regexp parser fixed in 2.15.4
    CVE-2026-86137 is an out-of-bounds read (CWE-125) in libxml2's xmlFAParsePosCharGroup function, in the NXT macro of the xmlregexp regular-expression engine, fixed in libxml2 2.15.4. It is triggered when an application uses libxml2 to parse a regular-expression pattern that reaches the character-group parsing code path; the high-complexity CVSS component indicates a carefully formed input is needed to reach the faulty read. The practical impact is minimal: the vector is local (AV:L) with no confidentiality or integrity impact and only limited availability loss, so the realistic worst case is a crash or partial disruption of the parsing process rather than code execution or data disclosure. Any software that ships, links, or bundles a version of libxml2 prior to 2.15.4 is affected, which includes a very large installed base given how widely the library is embedded. Exploitation status is quiet: there is no public proof of concept, the flaw is not in CISA's KEV, and EPSS puts exploitation probability at 0.1% over the next 30 days.
    · GNOME (libxml2 project) libxml2 all versions prior to 2.15.4 PoC mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.