https://seclists.org/oss-sec/2026/q3/657: Vulnerabilities fixed in libxml2-2.15.4
Published Sep 5, 2026
·Updated
Affected Software
1 affected component
Gnome libxml2<2.15.4
The listed issues affect libxml2 versions before 2.15.4. Updating to 2.15.4 addresses the security fixes described in the source.
CVE-2026-86137 covers an out-of-bounds read in xmlFAParsePosCharGroup. CVE-2026-86138 covers an integer overflow leading to a heap-based buffer overflow in xmlDictAddQString, CVE-2026-86139 covers an integer overflow in xmlURIEscapeStr, and CVE-2026-86140 is assigned to an issue in xmlSnprintfElements.