Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-86143

Опубликовано: 05 сент. 2026
Источник: redhat
CVSS3: 6.9
EPSS Низкий

Описание

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.

An integer overflow in the libxml2 xmlIO module occurs when data backlogs exceed maximum integer limits. This flaw passes negative length values to downstream write callbacks, creating an unsafe state that can lead to data corruption or compromise application confidentiality and integrity.

Отчет

Moderate impact: This flaw in libxml2, a widely used XML parsing library, is due to an integer overflow in write callbacks. This can lead to negative lengths being passed to write operations, potentially causing data integrity issues in applications that process untrusted XML input and utilize affected write callbacks. The impact is limited to applications that specifically trigger this overflow condition.

Меры по смягчению последствий

Cap process and cgroup memory so a process cannot build a ≥2 GiB libxml2 output backlog. Keep FORTIFY_SOURCE-built Red Hat binaries so some callback copies of the truncated length abort instead of corrupting memory

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libxml2Affected
Red Hat Enterprise Linux 10podmanNot affected
Red Hat Enterprise Linux 6libxml2Out of support scope
Red Hat Enterprise Linux 7libxml2Out of support scope
Red Hat Enterprise Linux 8container-tools:rhel8/podmanNot affected
Red Hat Enterprise Linux 8libxml2Fix deferred
Red Hat Enterprise Linux 9libxml2Affected
Red Hat Enterprise Linux 9podmanNot affected
Red Hat Hardened Imagesswift-langNot affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-192
https://bugzilla.redhat.com/show_bug.cgi?id=2528987libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks

EPSS

Процентиль: 2%
0.00119
Низкий

6.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.9
ubuntu
9 дней назад

(In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteC ...)

CVSS3: 6.9
nvd
11 дней назад

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.

msrc
10 дней назад

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.

CVSS3: 6.9
debian
11 дней назад

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteC ...

CVSS3: 6.9
github
11 дней назад

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.

EPSS

Процентиль: 2%
0.00119
Низкий

6.9 Medium

CVSS3