Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-86142

Опубликовано: 05 сент. 2026
Источник: redhat
CVSS3: 6.9

Описание

In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.

A flaw in libxml2's xmlXPtrEvalXPtrPart function allows a local attacker to cause a heap-based buffer overflow. An integer overflow while processing an oversized xpointer() expression leads to incorrect memory allocation and an out-of-bounds write, potentially resulting in information disclosure, data corruption, or a denial of service (DoS).

Отчет

A heap-based buffer overflow in libxml2's xmlXPtrEvalXPtrPart function enables an out-of-bounds write during the evaluation of oversized xpointer() expressions. The flaw is assigned a Moderate severity rating because exploitation strictly requires local access and complex, multi-gigabyte payload inputs, effectively mitigating the threat of remote or automated system compromise.

Меры по смягчению последствий

To mitigate this applications should avoid passing untrusted XPointer expressions into xmlXPtrEval or XInclude xpointer= attributes and strictly cap input length well below INT_MAX. Additionally, administrators should enforce process or cgroup memory limits to prevent the construction of multi-gigabyte scheme bodies, relying on heap allocator hardening rather than standard fortify flags, which cannot stop this byte-store loop.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libxml2Affected
Red Hat Enterprise Linux 10podmanNot affected
Red Hat Enterprise Linux 6libxml2Not affected
Red Hat Enterprise Linux 7libxml2Not affected
Red Hat Enterprise Linux 8container-tools:rhel8/podmanNot affected
Red Hat Enterprise Linux 8libxml2Not affected
Red Hat Enterprise Linux 9libxml2Fix deferred
Red Hat Enterprise Linux 9podmanNot affected
Red Hat Hardened Imagesswift-langNot affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-805
https://bugzilla.redhat.com/show_bug.cgi?id=2528990libxml2: libxml2: Heap-based buffer overflow in xmlXPtrEval due to xpointer length saturation

6.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.9
ubuntu
9 дней назад

(In libxml2 before 2.15.4, there is a heap-based buffer overflow in xml ...)

CVSS3: 6.9
nvd
11 дней назад

In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.

msrc
9 дней назад

In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.

CVSS3: 6.9
debian
11 дней назад

In libxml2 before 2.15.4, there is a heap-based buffer overflow in xml ...

CVSS3: 6.9
github
11 дней назад

In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.

6.9 Medium

CVSS3