CVE-2026-86138: Integer Overflow
Published Sep 5, 2026
·Updated
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
Affected Software
4 affected componentsFixes available
libxml2 libxml2<2.15.4
Xmlsoft Libxml2<2.15.4
Microsoft azl3 libxml2 2.11.5-10<2.11.5-11
2.11.5-11
Microsoft azl3 libxml2 2.11.5-11<2.11.5-11
2.11.5-11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.11.5-11
Event History
Sep 5, 2026
CVE Published
via MITRE·04:21 AM
Data Sourced
via MITRE·04:21 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 AM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 6, 2026
Data Sourced
via Microsoft·11:36 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·11:36 AM
DescriptionSeverity
Updated
via Microsoft·11:36 AM
Affected Software
Frequently Asked Questions
1
What level of access does an attacker need?
The attack vector is local and requires no privileges or user interaction. Exploitation has high attack complexity.
2
Which installations are affected?
Installations using libxml2 versions before 2.15.4 are affected. Version 2.15.4 is the first version indicated as not affected by the provided data.
3
How can I determine whether my environment is exposed?
Identify the libxml2 version in use by the affected application or system package. Versions earlier than 2.15.4 should be treated as affected.