CVE-2026-86139

Published: September 8, 2026Last modified: September 28, 2026

Description

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

Severity score breakdown

ParameterValue
Base score7.8
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibxml2Unknown (2.10.3-r2)
25 LTSlibxml2Unknown (2.13.8-r0)
Streamlibxml2Fixed (2.13.9-r6)
Hardened Containers23 LTSlibxml2Unknown (2.10.3-r2)
25 LTSlibxml2Unknown (2.13.8-r0)
Streamlibxml2Unknown (2.10.3-r2)

References

ON THIS PAGE