Stack-based Buffer Overflow in libxml2 Affects GNOME Software
CVE-2026-86140

8HIGH

Key Information:

Vendor

Xmlsoft

Status
Vendor
CVE Published:
5 September 2026

What is CVE-2026-86140?

The libxml2 library, prior to version 2.15.4, contains a stack-based buffer overflow in the xmlSnprintfElements function found in valid.c. This vulnerability may allow an attacker to exploit the overflow, potentially leading to arbitrary code execution or crashes in applications using libxml2. It is essential for users and developers utilizing affected versions to upgrade to version 2.15.4 or later to mitigate this vulnerability.

Affected Version(s)

libxml2 0 < 2.15.4

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.