[ALSA-2026:71585] Important: libxml2 security update
Type:
security
Severity:
important
Release date:
2026-09-25
Description:
The libxml2 library is a development toolbox providing the implementation of various XML standards. Security Fix(es): * libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow (CVE-2026-86138) * libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks (CVE-2026-86143) * libxml2: libxml2: Arbitrary code execution via stack-based buffer overflow in xmlSnprintfElements (CVE-2026-86140) * libxml2: libxml2: Heap-based buffer overflow in xmlXPtrEval due to xpointer length saturation (CVE-2026-86142) * libxml2: libxml2: Information disclosure, SSRF, or denial of service due to improper parseFlags propagation. (CVE-2026-86144) * libxml2: double-free/UAF in libxml2 Python bindings (CVE-2026-74860) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libxml2-2.9.13-14.el9_8.5.aarch64.rpm 592a4a2cd23c7902586757c954efce31c36c29ff40a836e4651e9531f37efc90
aarch64 libxml2-devel-2.9.13-14.el9_8.5.aarch64.rpm 8011149f43b501dc9fa3ab56dade6ef18655b7b9000e308981267cd794abcd91
aarch64 python3-libxml2-2.9.13-14.el9_8.5.aarch64.rpm be26e3dd410f73d9eb9e8f2abe46fb2dbf1c062864e9b5dcdb00d0b4f7d516ea
i686 libxml2-2.9.13-14.el9_8.5.i686.rpm 70a9dc1bfef6c5144e35b84755f247298df286d948654eca19a4b7fae6678303
i686 libxml2-devel-2.9.13-14.el9_8.5.i686.rpm 98dbebf420374723e51d4d14f70b33d81f96cded97f9241eb569533fdc281b95
ppc64le libxml2-2.9.13-14.el9_8.5.ppc64le.rpm 0be6240c2ba0c5bd913f4165cf85babfa10b5f27a0001506c3d6bd0027855e4d
ppc64le libxml2-devel-2.9.13-14.el9_8.5.ppc64le.rpm 45e992a9547c749fb6c35000754db42d5eb4468d25b3b6893e9def3a2dbb1dce
ppc64le python3-libxml2-2.9.13-14.el9_8.5.ppc64le.rpm a634885c4155fcc94d5c826f0efb788693aa0446be398ac366b8fae21dc09ab4
s390x libxml2-devel-2.9.13-14.el9_8.5.s390x.rpm b262d860939fe36f058bd3439ec1a6cb8b1583fc1d82b8604c6fe29948bcb5af
s390x python3-libxml2-2.9.13-14.el9_8.5.s390x.rpm bea4673a1cc62f0739f9967cbdc3e6045f4b2b9e04da7bdb3891653881aad634
s390x libxml2-2.9.13-14.el9_8.5.s390x.rpm e0c019668ffe6e542098cce311b81f377955020d133a4b66f97498e13fab6c2f
x86_64 python3-libxml2-2.9.13-14.el9_8.5.x86_64.rpm 158e7f10911eb52bd78e919643c49fe5e5fffdc6c43028d5fdfe799c425910b0
x86_64 libxml2-2.9.13-14.el9_8.5.x86_64.rpm 1f83ad048acd3419e17512d191768670ef22500ab464615c3a3fb0e9bf05b86b
x86_64 libxml2-devel-2.9.13-14.el9_8.5.x86_64.rpm f3f26dd68e08d2e2b5d277c4163b56f93721282dbf4d75a407d39f16f90c55ab
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.