ALSA-2026:71585
Dashboard / Vulnerabilities / ALSA-2026:71585
ALSA-2026:71585
Summary: Important: libxml2 security update
Details: The libxml2 library is a development toolbox providing the implementation of various XML standards. Security Fix(es): * libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow (CVE-2026-86138) * libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks (CVE-2026-86143) * libxml2: libxml2: Arbitrary code execution via stack-based buffer overflow in xmlSnprintfElements (CVE-2026-86140) * libxml2: libxml2: Heap-based buffer overflow in xmlXPtrEval due to xpointer length saturation (CVE-2026-86142) * libxml2: libxml2: Information disclosure, SSRF, or denial of service due to improper parseFlags propagation. (CVE-2026-86144) * libxml2: double-free/UAF in libxml2 Python bindings (CVE-2026-74860) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://access.redhat.com/errata/RHSA-2026:71585, https://access.redhat.com/security/cve/CVE-2026-74860, https://access.redhat.com/security/cve/CVE-2026-86138, https://access.redhat.com/security/cve/CVE-2026-86140, https://access.redhat.com/security/cve/CVE-2026-86142, https://access.redhat.com/security/cve/CVE-2026-86143, https://access.redhat.com/security/cve/CVE-2026-86144, https://bugzilla.redhat.com/2528986, https://bugzilla.redhat.com/2528987, https://bugzilla.redhat.com/2528989, https://bugzilla.redhat.com/2528990, https://bugzilla.redhat.com/2528992, https://bugzilla.redhat.com/2529697, https://errata.almalinux.org/9/ALSA-2026-71585.html
Affected packages
Package
Name: libxml2
Purl: pkg:rpm/almalinux/libxml2
Affected ranges
Type: ECOSYSTEM
Events:
