oss-sec mailing list archives

Vulnerabilities fixed in libxml2-2.15.4


From: Sam James <sam () gentoo org>
Date: Fri, 04 Sep 2026 18:35:56 +0100

From libxml2-2.15.4:

+v2.15.4: Sep 01 2026
+
+### Security
+
+- xmlregexp: Prevent out-of-bounds read in NXT macro
+- fix: add missing overflow checks in dict.c, uri.c, and valid.c
+- xmlregexp: Calc string length after null checking
+- xpointer: Check overflow in xmlXPtrEvalXPtrPart
+- xmlIO: Check for int overflow before calling writecallback
+- fix(xinclude): propagate parseFlags in xmlXIncludeProcess and xmlXIncludeProcessTree
+
+ [...]

I possess no further details.

sam

Attachment: signature.asc
Description:


Current thread: