Heap-based Buffer Overflow in libxml2 Affects GNOME Products
CVE-2026-86142

6.9MEDIUM

Key Information:

Vendor

Xmlsoft

Status
Vendor
CVE Published:
5 September 2026

What is CVE-2026-86142?

A heap-based buffer overflow vulnerability has been identified in libxml2 prior to version 2.15.4. This issue is triggered by the xmlXPtrEvalXPtrPart function, where an improper handling of xpointer length can lead to memory corruption. Potential attackers could exploit this flaw to execute arbitrary code or cause unexpected application behavior, making it essential for users to upgrade to the latest version to mitigate any risks associated with this vulnerability.

Affected Version(s)

libxml2 0 < 2.15.4

References

CVSS V3.1

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.