Home / mailingsPDF  

[USN-8910-1] libxml2 vulnerabilities

Posted on 08 October 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8910-1
October 08, 2026

libxml2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in libxml2.

Software Description:
- libxml2: GNOME XML library

Details:

Yirou Yang discovered that libxml2 incorrectly handled certain XML
catalogs. If a user or automated system was tricked into processing a
specially crafted XML catalog, an attacker could possibly use this issue to
cause libxml2 to crash, resulting in a denial of service. (CVE-2026-76781)

It was discovered that libxml2 incorrectly handled certain large qualified
names, leading to a heap-based buffer overflow. An attacker could possibly
use this issue to cause libxml2 to crash, resulting in a denial of service,
or possibly execute arbitrary code. (CVE-2026-86138)

It was discovered that libxml2 incorrectly handled escaping certain large
URI strings. An attacker could possibly use this issue to cause libxml2 to
use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-86139)

Xudong Cao and Meng Xu discovered that libxml2 incorrectly handled certain
large XPointer expressions, leading to a heap-based buffer overflow. An
attacker could possibly use this issue to cause libxml2 to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2026-86142)

Xudong Cao and Meng Xu discovered that libxml2 did not check for integer
overflows before passing output lengths to write callbacks. An attacker
could possibly use this issue to cause an application using libxml2 to
crash, resulting in a denial of service. (CVE-2026-86143)

It was discovered that libxml2 did not apply parser options, such as
disabling network access, when processing XInclude directives under certain
circumstances. An attacker could possibly use this issue to perform XML
external entity injection or server-side request forgery attacks, or cause
a denial of service. (CVE-2026-86144)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
libxml2-16 2.15.2+dfsg-0.1ubuntu0.3
libxml2-dev 2.15.2+dfsg-0.1ubuntu0.3
libxml2-source 2.15.2+dfsg-0.1ubuntu0.3

Ubuntu 24.04 LTS
libxml2 2.9.14+dfsg-1.3ubuntu3.10
libxml2-dev 2.9.14+dfsg-1.3ubuntu3.10

Ubuntu 22.04 LTS
libxml2 2.9.13+dfsg-1ubuntu0.14
libxml2-dev 2.9.13+dfsg-1ubuntu0.14

Ubuntu 20.04 LTS
libxml2 2.9.10+dfsg-5ubuntu0.20.04.10+esm6
Available with Ubuntu Pro
libxml2-dev 2.9.10+dfsg-5ubuntu0.20.04.10+esm6
Available with Ubuntu Pro

Ubuntu 18.04 LTS
libxml2 2.9.4+dfsg1-6.1ubuntu1.9+esm9
Available with Ubuntu Pro
libxml2-dev 2.9.4+dfsg1-6.1ubuntu1.9+esm9
Available with Ubuntu Pro

Ubuntu 16.04 LTS
libxml2 2.9.3+dfsg1-1ubuntu0.7+esm14
Available with Ubuntu Pro
libxml2-dev 2.9.3+dfsg1-1ubuntu0.7+esm14
Available with Ubuntu Pro

Ubuntu 14.04 LTS
libxml2 2.9.1+dfsg1-3ubuntu4.13+esm13
Available with Ubuntu Pro
libxml2-dev 2.9.1+dfsg1-3ubuntu4.13+esm13
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8910-1
CVE-2026-76781, CVE-2026-86138, CVE-2026-86139, CVE-2026-86142,
CVE-2026-86143, CVE-2026-86144

Package Information:
https://launchpad.net/ubuntu/+source/libxml2/2.15.2+dfsg-0.1ubuntu0.3
https://launchpad.net/ubuntu/+source/libxml2/2.9.14+dfsg-1.3ubuntu3.10
https://launchpad.net/ubuntu/+source/libxml2/2.9.13+dfsg-1ubuntu0.14

--===============1371885473631340433==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP