diff --git a/meta/recipes-core/libxml/libxml2/CVE-2026-86142.patch b/meta/recipes-core/libxml/libxml2/CVE-2026-86142.patch
new file mode 100644
index 0000000000..d63d8cdceb
--- /dev/null
+++ b/meta/recipes-core/libxml/libxml2/CVE-2026-86142.patch
@@ -0,0 +1,37 @@
+From 51f0e78349cbbc9081f14e02f440733e5880fb3d Mon Sep 17 00:00:00 2001
+From: Daniel Garcia Moreno <daniel.garcia@suse.com>
+Date: Mon, 4 May 2026 09:32:43 +0200
+Subject: [PATCH] xpointer: Check overflow in xmlXPtrEvalXPtrPart
+
+Fix https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1113
+
+CVE: CVE-2026-86142
+Upstream-Status: Backport [https://github.com/GNOME/libxml2/commit/6b3a736c0edc74ceec3d82f5252499d7911b3a58]
+
+Backport Changes:
+- Use xmlXPathErr(ctxt, XPATH_MEMORY_ERROR) because the Scarthgap xpointer implementation does not provide the newer xmlXPathPErrMemory() call shape. This preserves the XPath parser error state as well as reporting the allocation failure.
+
+(cherry picked from commit 6b3a736c0edc74ceec3d82f5252499d7911b3a58)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ xpointer.c | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+diff --git a/xpointer.c b/xpointer.c
+index 6e1e5f46..f5457c9f 100644
+--- a/xpointer.c
++++ b/xpointer.c
+@@ -956,6 +956,13 @@ xmlXPtrEvalXPtrPart(xmlXPathParserContextPtr ctxt, xmlChar *name) {
+     level = 1;
+ 
+     len = xmlStrlen(ctxt->cur);
++    /* Overflow in xmlStrlen */
++    if (len == 0 && ctxt->cur != NULL && *ctxt->cur != 0) {
++        xmlXPathErr(ctxt, XPATH_MEMORY_ERROR);
++        xmlFree(name);
++        return;
++    }
++
+     len++;
+     buffer = (xmlChar *) xmlMallocAtomic(len);
+     if (buffer == NULL) {
diff --git a/meta/recipes-core/libxml/libxml2_2.12.10.bb b/meta/recipes-core/libxml/libxml2_2.12.10.bb
index 49a1a8dbaa..881b60133d 100644
--- a/meta/recipes-core/libxml/libxml2_2.12.10.bb
+++ b/meta/recipes-core/libxml/libxml2_2.12.10.bb
@@ -36,6 +36,7 @@ SRC_URI += "http://www.w3.org/XML/Test/xmlts20130923.tar;subdir=${BP};name=testt
            file://CVE-2026-86138.patch \
            file://CVE-2026-86140.patch \
            file://CVE-2026-86141.patch \
+           file://CVE-2026-86142.patch \
            "
 
 SRC_URI[archive.sha256sum] = "c3d8c0c34aa39098f66576fe51969db12a5100b956233dc56506f7a8679be995"
