NULL Pointer Dereference in libxml2 Affects GNOME Products
CVE-2026-86141
2.9LOW
What is CVE-2026-86141?
A security vulnerability exists in xmlregexp within libxml2 prior to version 2.15.4, where a NULL pointer dereference occurs in the xmlRegNewParserCtxt function following a strdup failure. The defect arises from not calculating the length of a string after performing a NULL check, potentially leading to system instability or compromised application behavior.
Affected Version(s)
libxml2 0 < 2.15.4
