USN-8891-1: librsvg flaw risks crashes or code execution
Ubuntu fixes a librsvg flaw (CVE-2026-96889) that opens the door to crashes or code execution via malicious SVG files. Updates for 24.04 and 26.04 LTS.
UptimeMag editorial team · 7 October 2026 · 1 min read

Ubuntu has published advisory USN-8891-1 for a vulnerability in librsvg, the library used to render SVG files on Ubuntu 24.04 LTS and 26.04 LTS. This affects anyone managing servers or workstations running packages that rely on librsvg to generate previews, icons, or process graphical content uploaded by users: a malicious SVG file can be enough to crash the process or, in the worst case, execute code with the permissions of the user who opens it.
The issue
According to the official Ubuntu advisory, the library incorrectly handles duplicate XML entity declarations when processing SVG documents with nested XML inclusions. An attacker can exploit this behaviour to cause a denial of service or, possibly, execute arbitrary code. The flaw is tracked as CVE-2026-96889.
Affected packages and fixed versions
| Ubuntu release | Codename | Package | Fixed version |
|---|---|---|---|
| 26.04 LTS | resolute | librsvg2-2 | 2.61.3+dfsg-3ubuntu0.1 |
| 24.04 LTS | noble | librsvg2-2 | 2.58.0+dfsg-1ubuntu0.1 |
How to update
According to Ubuntu's instructions, a standard system update will generally apply all the necessary changes:
sudo apt update
sudo apt upgrade
After updating, it's worth checking the installed version with dpkg -l librsvg2-2 to confirm it matches the one in the table above.
Ubuntu notes that Ubuntu Pro offers ten years of security coverage for over 25,000 packages in the Main and Universe repositories, free for up to five machines.
For full technical details and CVE references, the source is the official Ubuntu Security Notices advisory USN-8891-1, published on 6 October 2026 at ubuntu.com/security/notices/USN-8891-1.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.