CVE-2026-86142: Buffer Overflow
In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.11.5-11
Event History
Frequently Asked Questions
Which deployments are affected?
Deployments using libxml2 versions before 2.15.4 are affected. The issue is in xmlXPtrEvalXPtrPart during XPointer evaluation.
What access does an attacker need?
The provided vector indicates local attack access, no privileges, and no user interaction. Exploitation has high attack complexity.
What is the recommended remediation?
Update libxml2 to version 2.15.4 or later. The referenced comparison and commit cover the changes between 2.15.3 and 2.15.4.
What could successful exploitation impact?
The vulnerability is a heap-based buffer overflow. The supplied severity vector indicates high confidentiality and integrity impact, with low availability impact.