Advisories ยป MGASA-2026-0459

Updated libxml2 packages fix security vulnerabilities

Publication date: 28 Sep 2026
Modification date: 28 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-11979 , CVE-2026-86137 , CVE-2026-86138 , CVE-2026-86139 , CVE-2026-86140 , CVE-2026-86141 , CVE-2026-86142 , CVE-2026-86143 , CVE-2026-86144

Description

The updated packages fix several security issues:
Stack-Based Buffer Overflow in libxml2. (CVE-2026-11979)
In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds
read, aka an out-of-bounds read in the NXT macro in xmlregexp.
(CVE-2026-86137)
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer
overflow and resultant heap-based buffer overflow. (CVE-2026-86138)
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer
overflow. (CVE-2026-86139)
In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat
stack-based buffer overflow. (CVE-2026-86140)
xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in
xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate
a string length after NULL checking. (CVE-2026-86141)
In libxml2 before 2.15.4, there is a heap-based buffer overflow in
xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
(CVE-2026-86142)
In xmlIO in libxml2 before 2.15.4, an inconsistency in
xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach
write callbacks, aka a lack of a check for integer overflow before
calling writecallback. This has security relevance for many types of
uses of that length value within a callback. (CVE-2026-86143)
In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and
xmlXIncludeProcessTree do not propagate parseFlags. This has security
relevance for, for example, the XML_PARSE_NONET flag, if (without it) a
custom resource loader accesses the internet and triggers XML external
entity injection, SSRF, or a denial of service (e.g., for an
attacker-controlled internet resource that is intentionally slow).
(CVE-2026-86144)
                

References

SRPMS

10/core