#1146744 libxml2: CVE-2026-86137 CVE-2026-86138 CVE-2026-86139 CVE-2026-86140 CVE-2026-86141 CVE-2026-86142 CVE-2026-86143 CVE-2026-86144

#1146744#5
Date:
2026-09-05 09:18:47 UTC
From:
To:
Hi,

The following vulnerabilities were published for libxml2.

CVE-2026-86137[0]:
| In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-
| bounds read, aka an out-of-bounds read in the NXT macro in
| xmlregexp.


CVE-2026-86138[1]:
| In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer
| overflow and resultant heap-based buffer overflow.


CVE-2026-86139[2]:
| In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer
| overflow.


CVE-2026-86140[3]:
| In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a
| strcat stack-based buffer overflow.


CVE-2026-86141[4]:
| xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in
| xmlRegNewParserCtxt after a strdup failure, i.e., it does not
| calculate a string length after NULL checking.


CVE-2026-86142[5]:
| In libxml2 before 2.15.4, there is a heap-based buffer overflow in
| xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length
| saturation.


CVE-2026-86143[6]:
| In xmlIO in libxml2 before 2.15.4, an inconsistency in
| xmlOutputWriteCallback and xmlBufUse causes negative lengths to
| reach write callbacks, aka a lack of a check for integer overflow
| before calling writecallback. This has security relevance for many
| types of uses of that length value within a callback.


CVE-2026-86144[7]:
| In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and
| xmlXIncludeProcessTree do not propagate parseFlags. This has
| security relevance for, for example, the XML_PARSE_NONET flag, if
| (without it) a custom resource loader accesses the internet and
| triggers XML external entity injection, SSRF, or a denial of service
| (e.g., for an attacker-controlled internet resource that is
| intentionally slow).


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-86137
https://www.cve.org/CVERecord?id=CVE-2026-86137
[1] https://security-tracker.debian.org/tracker/CVE-2026-86138
https://www.cve.org/CVERecord?id=CVE-2026-86138
[2] https://security-tracker.debian.org/tracker/CVE-2026-86139
https://www.cve.org/CVERecord?id=CVE-2026-86139
[3] https://security-tracker.debian.org/tracker/CVE-2026-86140
https://www.cve.org/CVERecord?id=CVE-2026-86140
[4] https://security-tracker.debian.org/tracker/CVE-2026-86141
https://www.cve.org/CVERecord?id=CVE-2026-86141
[5] https://security-tracker.debian.org/tracker/CVE-2026-86142
https://www.cve.org/CVERecord?id=CVE-2026-86142
[6] https://security-tracker.debian.org/tracker/CVE-2026-86143
https://www.cve.org/CVERecord?id=CVE-2026-86143
[7] https://security-tracker.debian.org/tracker/CVE-2026-86144
https://www.cve.org/CVERecord?id=CVE-2026-86144

Regards,
Salvatore

#1146744#10
Date:
2026-09-05 18:34:31 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libxml2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1146744@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Aron Xu <aron@debian.org> (supplier of updated libxml2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 06 Sep 2026 01:58:14 +0800
Source: libxml2
Architecture: source
Version: 2.15.4+dfsg-1
Distribution: unstable
Urgency: high
Maintainer: Debian XML/SGML Group <debian-xml-sgml-pkgs@lists.alioth.debian.org>
Changed-By: Aron Xu <aron@debian.org>
Closes: 1146744
Changes:
 libxml2 (2.15.4+dfsg-1) unstable; urgency=high
 .
   * New upstream bug fix release. Closes: #1146744.
     Security fixes:
     - CVE-2026-86137: xmlregexp: out-of-bounds read in the NXT macro
       (xmlFAParsePosCharGroup).
     - CVE-2026-86138: dict: integer overflow in xmlDictAddQString leading
       to a heap-based buffer overflow.
     - CVE-2026-86139: uri: integer overflow in xmlURIEscapeStr.
     - CVE-2026-86140: valid: stack-based buffer overflow through unchecked
       strcat in xmlSnprintfElements.
     - CVE-2026-86141: xmlregexp: NULL pointer dereference in
       xmlRegNewParserCtxt.
     - CVE-2026-86142: xpointer: heap-based buffer overflow in
       xmlXPtrEvalXPtrPart.
     - CVE-2026-86143: xmlIO: missing integer overflow check before calling
       the write callback.
     - CVE-2026-86144: xinclude: parse flags such as XML_PARSE_NONET were
       not propagated by xmlXIncludeProcess and xmlXIncludeProcessTree.
     - CVE-2026-11979: xmlcatalog: stack-based buffer overflows in --shell
       command handling.
   * d/control: bump Standards-Version to 4.7.4, no changes needed.
Checksums-Sha1:
 3f75c5cdec4a3777bec31c9af5feb52d725647ec 2738 libxml2_2.15.4+dfsg-1.dsc
 d5d2954d7e9e7f4501f6d96469a9c6475232e76a 2367580 libxml2_2.15.4+dfsg.orig.tar.xz
 99106d472c022fc3d0aa6a917900dcca3549ab4a 36420 libxml2_2.15.4+dfsg-1.debian.tar.xz
 b006ae929d73e1ee4793e4fc25d1eee03fb8369f 5904 libxml2_2.15.4+dfsg-1_source.buildinfo
Checksums-Sha256:
 430fa25d8bb4a31eaf3f314c40fe12a1d0ea19d15576d90c95490e79fcc1d5d1 2738 libxml2_2.15.4+dfsg-1.dsc
 5868d20db42ee21e4881bc53050c7fa226286a277cb3d0543f76b81f7571e934 2367580 libxml2_2.15.4+dfsg.orig.tar.xz
 a125823450895c0785596a6fce26931ab0a369c82da4d6cfa6bbdac782ed9010 36420 libxml2_2.15.4+dfsg-1.debian.tar.xz
 79deddde8b8d83a8d4dfb2e3f2d7bf6ae1a067dcaac88496cc6bde8dc48e1496 5904 libxml2_2.15.4+dfsg-1_source.buildinfo
Files:
 cbdf4a3815ac31cd5ec1b1dac11717eb 2738 libs optional libxml2_2.15.4+dfsg-1.dsc
 0a853c709c8a11e695f7e34e000aa0c2 2367580 libs optional libxml2_2.15.4+dfsg.orig.tar.xz
 dda75bd7e9a40bdd95173c914662548d 36420 libs optional libxml2_2.15.4+dfsg-1.debian.tar.xz
 2e007b227ff9676d03b0eee87f88861e 5904 libs optional libxml2_2.15.4+dfsg-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEExq6D0hxncEPaPayX+GQ1dHE8m64FAmqcXLgACgkQ+GQ1dHE8
m65DCgf/UqWbYJpUcujM0us5rJFOTB+ezXYIF0CJB57bU/WCpX+WxRvdSYWv5A49
jCccGObWixHr4NoHZL/jYIwUXEv3/8l3sWJLpxcDP1K14PdjOzlmP8N6sddCOpzA
aKn27J9Xd7JN0UeVRkE6an0O/M6etwz5I7B40P7ibYD4UJAPVYKt38+lGIZGTecy
jAEh6et38QIQhpY8C8lZajQb1jJfcedqRMKqC3YHsCq/uAnKca0YXRk7lRw/AOR3
fiqDYyrn7lUoI2uoAYy4UjZvUZnbLiDVSz9pDlnJt3ycKzLBiiIVUAd3h5YdS4Au
kqkQ3zoysMh0xMCWWEcWx9Qxuxe8zw==
=64UA
-----END PGP SIGNATURE-----