Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-86139

Опубликовано: 05 сент. 2026
Источник: redhat
CVSS3: 6.9

Описание

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

A flaw was found in libxml2. An integer overflow vulnerability exists in the xmlURIEscapeStr function within uri.c. This flaw could potentially lead to memory corruption, allowing an attacker to achieve information disclosure or arbitrary code execution.

Отчет

An issue within the libxml2 xmlURIEscapeStr function could lead to arbitrary code execution. Despite the severe potential impact, the overall vulnerability is rated Moderate due to its high attack complexity and the strict prerequisite of local system access, which collectively constrain its exploitability in standard Red Hat environments.

Меры по смягчению последствий

To mitigate this developers must strictly cap URI and path lengths before passing data to libxml2 helpers to ensure multi-gigabyte strings cannot reach the vulnerable function. Furthermore, administrators should enforce strict process or cgroup memory limits to structurally prevent applications from allocating the excessively large buffers required to exceed maximum integer boundaries during string processing.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libxml2Not affected
Red Hat Enterprise Linux 10podmanNot affected
Red Hat Enterprise Linux 6libxml2Not affected
Red Hat Enterprise Linux 7libxml2Not affected
Red Hat Enterprise Linux 8container-tools:rhel8/podmanNot affected
Red Hat Enterprise Linux 8libxml2Not affected
Red Hat Enterprise Linux 9libxml2Not affected
Red Hat Enterprise Linux 9podmanNot affected
Red Hat Hardened Imagesswift-langNot affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2528991libxml2: libxml2: Integer overflow in xmlURIEscapeStr may lead to arbitrary code execution

6.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.9
ubuntu
16 дней назад

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

CVSS3: 6.9
nvd
16 дней назад

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

msrc
13 дней назад

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

CVSS3: 6.9
debian
16 дней назад

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer over ...

CVSS3: 6.9
github
16 дней назад

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

6.9 Medium

CVSS3