CVE-2026-86142: Buffer Overflow
Published Sep 5, 2026
·Updated
In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
Affected Software
1 affected component
libxml2 libxml2<2.15.4
Event History
Sep 5, 2026
CVE Published
via MITRE·04:29 AM
Data Sourced
via MITRE·04:29 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Deployments using libxml2 versions before 2.15.4 are affected. The issue is in xmlXPtrEvalXPtrPart during XPointer evaluation.
2
What access does an attacker need?
The provided vector indicates local attack access, no privileges, and no user interaction. Exploitation has high attack complexity.
3
What is the recommended remediation?
Update libxml2 to version 2.15.4 or later. The referenced comparison and commit cover the changes between 2.15.3 and 2.15.4.
4
What could successful exploitation impact?
The vulnerability is a heap-based buffer overflow. The supplied severity vector indicates high confidentiality and integrity impact, with low availability impact.