SB20260925164 - openEuler 24.03 LTS SP4 update for libxml2



SB20260925164 - openEuler 24.03 LTS SP4 update for libxml2

Published: September 25, 2026

Security Bulletin ID SB20260925164
CSH Severity
High
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 25% Medium 75%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 vulnerabilities.


1) Integer overflow (CVE-ID: CVE-2026-17705)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in libxml component in Google Chrome. A remote attacker can trick the victim to open a specially crafted web page, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


2) Out-of-bounds read (CVE-ID: CVE-2026-86137)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in the NXT macro in xmlregexp when processing input. A remote attacker can provide crafted input to cause a denial of service.


3) Heap-based buffer overflow (CVE-ID: CVE-2026-86138)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an integer overflow and resultant heap-based buffer overflow in xmlDictAddQString in dict.c when processing input. A remote attacker can provide crafted input to cause a denial of service.


4) Stack-based buffer overflow (CVE-ID: CVE-2026-86140)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a stack-based buffer overflow in xmlSnprintfElements in valid.c when processing input. A remote attacker can provide crafted input to cause a denial of service.


Remediation

Install update from vendor's website.