CVE-2026-86142

Published: September 8, 2026Last modified: September 28, 2026

Description

In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.

Severity score breakdown

ParameterValue
Base score7.8
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibxml2Unknown (2.10.3-r2)
25 LTSlibxml2Unknown (2.13.8-r0)
Streamlibxml2Fixed (2.13.9-r6)
Hardened Containers23 LTSlibxml2Unknown (2.10.3-r2)
25 LTSlibxml2Unknown (2.13.8-r0)
Streamlibxml2Unknown (2.10.3-r2)

References

ON THIS PAGE