CVE-2026-86138: Integer Overflow
Published Sep 5, 2026
·Updated
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
Affected Software
1 affected component
libxml2 libxml2<2.15.4
Event History
Sep 5, 2026
CVE Published
via MITRE·04:21 AM
Data Sourced
via MITRE·04:21 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The attack vector is local and requires no privileges or user interaction. Exploitation has high attack complexity.
2
Which installations are affected?
Installations using libxml2 versions before 2.15.4 are affected. Version 2.15.4 is the first version indicated as not affected by the provided data.
3
How can I determine whether my environment is exposed?
Identify the libxml2 version in use by the affected application or system package. Versions earlier than 2.15.4 should be treated as affected.