CVE-2026-86141: Null Pointer Dereference
Published Sep 5, 2026
·Updated
xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.
Affected Software
1 affected component
Gnome libxml2<2.15.4
Event History
Sep 5, 2026
CVE Published
via MITRE·04:27 AM
Data Sourced
via MITRE·04:27 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
Installations using libxml2 versions before 2.15.4 are affected in the xmlregexp component.
2
What access and conditions are required for exploitation?
The supplied vector indicates local access and high attack complexity. It does not require privileges or user interaction.
3
What is the expected impact?
The reported impact is limited to availability. No confidentiality or integrity impact is indicated.
4
What should be done to remediate the issue?
Update libxml2 to version 2.15.4 or later.