[ALSA-2026:71586] Important: libxml2 security update
Type:
security
Severity:
important
Release date:
2026-09-25
Description:
The libxml2 library is a development toolbox providing the implementation of various XML standards. Security Fix(es): * libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow (CVE-2026-86138) * libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks (CVE-2026-86143) * libxml2: libxml2: Arbitrary code execution via stack-based buffer overflow in xmlSnprintfElements (CVE-2026-86140) * libxml2: libxml2: Heap-based buffer overflow in xmlXPtrEval due to xpointer length saturation (CVE-2026-86142) * libxml2: libxml2: Information disclosure, SSRF, or denial of service due to improper parseFlags propagation. (CVE-2026-86144) * libxml2: double-free/UAF in libxml2 Python bindings (CVE-2026-74860) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 python3-libxml2-2.12.5-10.el10_2.4.aarch64.rpm 45f80065ebaaf743999822763556f9d622b92a0d72adcb17493d861bca02e3a2
aarch64 libxml2-devel-2.12.5-10.el10_2.4.aarch64.rpm 8c0220464b81fd92a36a11b9c1767758d23e10f3560dcab388ac630e2ec40f1b
aarch64 libxml2-static-2.12.5-10.el10_2.4.aarch64.rpm c34359eafb1a06c730d9a73454d767e42cf6a59905f3312c8c5b6c7ae0970b10
aarch64 libxml2-2.12.5-10.el10_2.4.aarch64.rpm e725f4b0b4b1571013dcd93b0c6b56130a05d434dc116764d76e19da61590cb2
ppc64le libxml2-2.12.5-10.el10_2.4.ppc64le.rpm 877012301478400dd2359ff1de6f9a73e0092d7416f1271db6428ef3d3a4029e
ppc64le python3-libxml2-2.12.5-10.el10_2.4.ppc64le.rpm 9b472ef8e17a8a2e65e9c41a6c165398a4c4e49e33252ca0a3bee1e12d71a17b
ppc64le libxml2-static-2.12.5-10.el10_2.4.ppc64le.rpm b78cf3f719807d060ac02b8fc1fc40f64bef3d310146089e823ce251552ff469
ppc64le libxml2-devel-2.12.5-10.el10_2.4.ppc64le.rpm db1116349c8fc0bdda8a0a813bd2ea1ac16f75991b7cae5f6cfd3bfbcdacd0cc
s390x python3-libxml2-2.12.5-10.el10_2.4.s390x.rpm 74b802283df8f24ebd3dec33e8f1157d204622e3d7ebca1a290d05f967ac47ab
s390x libxml2-devel-2.12.5-10.el10_2.4.s390x.rpm 8c046755f02c6676a2869f9af79710c4941f681de17f0e1d4f517bfdf561297a
s390x libxml2-2.12.5-10.el10_2.4.s390x.rpm ed7092003ebb0beace6229cc93adfe51fb10744bb810fed31756450dbe395514
s390x libxml2-static-2.12.5-10.el10_2.4.s390x.rpm fcb6ff4b1a20ea9d97f988fa520f33867f0070fadc454ed26addbc370bc605cc
x86_64 libxml2-devel-2.12.5-10.el10_2.4.x86_64.rpm 41218c2e0c1004e63c3418737065f06af4e1cfdeb5623a868e3208e48fc471e1
x86_64 libxml2-static-2.12.5-10.el10_2.4.x86_64.rpm 6b53e8cdb17f35dbb6b40b8fd1e5f11211727b8dd3bf6ac3cc2978a3fac2e86f
x86_64 libxml2-2.12.5-10.el10_2.4.x86_64.rpm 8005a3d5d975a61ec37e5906bb83e4aebfe7eedd88f9cda68327243f7c58a922
x86_64 python3-libxml2-2.12.5-10.el10_2.4.x86_64.rpm b65ed26a47a3d553d04dbf13d7f217c90f3da37e7fb535423ce8b15a0a969538
x86_64_v2 libxml2-2.12.5-10.el10_2.4.x86_64_v2.rpm 0a5372bb724125d4e2aef355ab1484f5cec88ff06ef33d3852316b32e1ce117b
x86_64_v2 python3-libxml2-2.12.5-10.el10_2.4.x86_64_v2.rpm 1cfe01e9718c5cddd5a05a3b045bacf15d8c60765ea937d58ea7c04421562c0c
x86_64_v2 libxml2-static-2.12.5-10.el10_2.4.x86_64_v2.rpm 83a7f9ee41c04dbb9eaaed9e2d7e1dd98f3c417f19bc03e5a8ab1dfc783a32f0
x86_64_v2 libxml2-devel-2.12.5-10.el10_2.4.x86_64_v2.rpm a7c4c6ef142c7328dcd7e912f1235c65daa6a240c77174d5e530fed61f74efa3
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.