[ALSA-2026:71641] Important: libxml2 security update
Type:
security
Severity:
important
Release date:
2026-09-25
Description:
The libxml2 library is a development toolbox providing the implementation of various XML standards. Security Fix(es): * libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow (CVE-2026-86138) * libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks (CVE-2026-86143) * libxml2: libxml2: Arbitrary code execution via stack-based buffer overflow in xmlSnprintfElements (CVE-2026-86140) * libxml2: libxml2: Information disclosure, SSRF, or denial of service due to improper parseFlags propagation. (CVE-2026-86144) * libxml2: double-free/UAF in libxml2 Python bindings (CVE-2026-74860) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 python3-libxml2-2.9.7-21.el8_10.9.aarch64.rpm 011cf6dfed92566f99426a138f2306a248d8eec112bc585200e59b80c4c84e38
aarch64 libxml2-devel-2.9.7-21.el8_10.9.aarch64.rpm d3f3f83b2d0a503385092068eeb531f1e1a2764664e21be0b81d1fbcf1ba7cce
aarch64 libxml2-2.9.7-21.el8_10.9.aarch64.rpm e9995b8c8cf2343af51d58406815df02dc90713c911cf215ba8bd3a4a4a9c673
i686 libxml2-devel-2.9.7-21.el8_10.9.i686.rpm 6277c663ce71fd206829b5d908fb64362fb9bc550eee09024730c2aaca2c2592
i686 libxml2-2.9.7-21.el8_10.9.i686.rpm d369af087dd6c639a155927cc5ab0e3ff13a24887cac2ad45cda81146bf66e71
ppc64le libxml2-devel-2.9.7-21.el8_10.9.ppc64le.rpm 3cbbd57e89ecb2e53d7fe9602300d91b0f7e76da1334347312f3cf21150aca94
ppc64le libxml2-2.9.7-21.el8_10.9.ppc64le.rpm 870a905e3b47c3ea991a7b0c9e6b5789db514a321a0aaf6491dfe59194fb53cd
ppc64le python3-libxml2-2.9.7-21.el8_10.9.ppc64le.rpm e06c290b8ea96b836da6672d791d8979b21b67591e52eb02cfe281ae11a332e9
s390x python3-libxml2-2.9.7-21.el8_10.9.s390x.rpm 3e6aa16752c2eb6f92200e1bf29b7c28ea34c9b601792413c03559f3a7e47b1b
s390x libxml2-2.9.7-21.el8_10.9.s390x.rpm c23416b0018f39768ad9c55ef27ff2dcbf0e70cd1878dc8c9e36a6b28fa0873b
s390x libxml2-devel-2.9.7-21.el8_10.9.s390x.rpm d95e38d9d77ab0fd9048d4625b5270a4ad8325e4c13ea57357f5c3a6b3a59aec
x86_64 libxml2-devel-2.9.7-21.el8_10.9.x86_64.rpm 8e4abbe9efcd952b647e7bc989095a46f723f47d304ed0d4965c701f024455f3
x86_64 libxml2-2.9.7-21.el8_10.9.x86_64.rpm b2396a179f94e995b442509783a1bc54e8e866266baacd60b1defbd23c5b9bd4
x86_64 python3-libxml2-2.9.7-21.el8_10.9.x86_64.rpm f3fe59b6bb4fa6404633bddd045dece89f3e4a7d36c7944e322dc7fa9a055595
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.