Source: libxml2 Version: 2.15.3+dfsg-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for libxml2. CVE-2026-86137[0]: | In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of- | bounds read, aka an out-of-bounds read in the NXT macro in | xmlregexp. CVE-2026-86138[1]: | In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer | overflow and resultant heap-based buffer overflow. CVE-2026-86139[2]: | In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer | overflow. CVE-2026-86140[3]: | In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a | strcat stack-based buffer overflow. CVE-2026-86141[4]: | xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in | xmlRegNewParserCtxt after a strdup failure, i.e., it does not | calculate a string length after NULL checking. CVE-2026-86142[5]: | In libxml2 before 2.15.4, there is a heap-based buffer overflow in | xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length | saturation. CVE-2026-86143[6]: | In xmlIO in libxml2 before 2.15.4, an inconsistency in | xmlOutputWriteCallback and xmlBufUse causes negative lengths to | reach write callbacks, aka a lack of a check for integer overflow | before calling writecallback. This has security relevance for many | types of uses of that length value within a callback. CVE-2026-86144[7]: | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and | xmlXIncludeProcessTree do not propagate parseFlags. This has | security relevance for, for example, the XML_PARSE_NONET flag, if | (without it) a custom resource loader accesses the internet and | triggers XML external entity injection, SSRF, or a denial of service | (e.g., for an attacker-controlled internet resource that is | intentionally slow). If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-86137 https://www.cve.org/CVERecord?id=CVE-2026-86137 [1] https://security-tracker.debian.org/tracker/CVE-2026-86138 https://www.cve.org/CVERecord?id=CVE-2026-86138 [2] https://security-tracker.debian.org/tracker/CVE-2026-86139 https://www.cve.org/CVERecord?id=CVE-2026-86139 [3] https://security-tracker.debian.org/tracker/CVE-2026-86140 https://www.cve.org/CVERecord?id=CVE-2026-86140 [4] https://security-tracker.debian.org/tracker/CVE-2026-86141 https://www.cve.org/CVERecord?id=CVE-2026-86141 [5] https://security-tracker.debian.org/tracker/CVE-2026-86142 https://www.cve.org/CVERecord?id=CVE-2026-86142 [6] https://security-tracker.debian.org/tracker/CVE-2026-86143 https://www.cve.org/CVERecord?id=CVE-2026-86143 [7] https://security-tracker.debian.org/tracker/CVE-2026-86144 https://www.cve.org/CVERecord?id=CVE-2026-86144 Regards, Salvatore

