Heap-Based Buffer Overflow in libxml2 Affecting GNOME Products
CVE-2026-86138

6.9MEDIUM

Key Information:

Vendor

Xmlsoft

Status
Vendor
CVE Published:
5 September 2026

What is CVE-2026-86138?

A vulnerability in libxml2, prior to version 2.15.4, involves an integer overflow in the xmlDictAddQString function within dict.c. This flaw can lead to a heap-based buffer overflow, which may allow an attacker to execute arbitrary code or cause a denial-of-service condition. Users are strongly advised to upgrade to the patched version to mitigate any potential risks associated with this vulnerability.

Affected Version(s)

libxml2 0 < 2.15.4

References

CVSS V3.1

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.