CVE Vulnerabilities

CVE-2026-86141

Unchecked Return Value

Published: Sep 05, 2026 | Modified: Sep 15, 2026
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
2.9 LOW
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.

Weakness

The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.

Affected Software

NameVendorStart VersionEnd Version
Libxml2Xmlsoft*2.15.4 (excluding)
Red Hat Hardened ImagesRedHatlibxml2-main-2.15.4-0.1.hum1*
Libxml2Ubuntuupstream*

Potential Mitigations

References