News

USN-8910-1: libxml2 flaws, DoS risk and possible code execution

Ubuntu fixes six libxml2 flaws across all releases from 14.04 to 26.04 LTS: two could lead to code execution.

UptimeMag editorial team · 9 October 2026 · 2 min read

USN-8910-1: falle in libxml2, rischio DoS e possibile esecuzione di codice

On 8 October 2026 Ubuntu published advisory USN-8910-1, fixing six vulnerabilities in libxml2, the GNOME library for XML parsing used by PHP, many web applications and numerous system tools. Anyone managing Ubuntu servers—particularly those running LAMP/LEMP stacks or services that process XML from external sources—needs to update.

The vulnerabilities

According to the official Ubuntu advisory:

  • CVE-2026-76781: incorrect handling of specially crafted XML catalogues, discovered by Yirou Yang. Can cause a crash (DoS) if a user or an automated system is tricked into processing the malicious catalogue.
  • CVE-2026-86138: heap-based buffer overflow when handling very long qualified names. Risk of a crash or, possibly, arbitrary code execution.
  • CVE-2026-86139: incorrect handling of escaping for very long URI strings, leading to excessive resource consumption. Affects only Ubuntu 26.04 LTS.
  • CVE-2026-86142: heap-based buffer overflow when handling very long XPointer expressions, discovered by Xudong Cao and Meng Xu. Again, risk of a crash or code execution.
  • CVE-2026-86143: missing integer overflow check before passing output lengths to write callbacks, risking a crash of the application using libxml2.
  • CVE-2026-86144: parser options (such as disabling network access) are not applied under certain circumstances when processing XInclude directives. This could lead to XML external entity injection, server-side request forgery, or denial of service.

Fixed packages

Release Package Fixed version
26.04 LTS libxml2-16 / libxml2-dev / libxml2-source 2.15.2+dfsg-0.1ubuntu0.3
24.04 LTS libxml2 / libxml2-dev 2.9.14+dfsg-1.3ubuntu3.10
22.04 LTS libxml2 / libxml2-dev 2.9.13+dfsg-1ubuntu0.14
20.04 LTS (Ubuntu Pro) libxml2 / libxml2-dev 2.9.10+dfsg-5ubuntu0.20.04.10+esm6
18.04 LTS (Ubuntu Pro) libxml2 / libxml2-dev 2.9.4+dfsg1-6.1ubuntu1.9+esm9
16.04 LTS (Ubuntu Pro Legacy) libxml2 / libxml2-dev 2.9.3+dfsg1-1ubuntu0.7+esm14
14.04 LTS (Ubuntu Pro Legacy) libxml2 / libxml2-dev 2.9.1+dfsg1-3ubuntu4.13+esm13

For release 20.04 and earlier, the fix is only available with an Ubuntu Pro subscription (for 16.04 and 14.04, the Legacy Support add-on is also required).

What to do

A standard system update (apt update && apt upgrade) applies the fixes on releases still under standard support. On 26.04, 24.04 and 22.04 LTS, the normal patching cycle is sufficient; after upgrading, it's advisable to restart any services linked against libxml2, particularly PHP-FPM and Apache/Nginx with XML modules enabled.

Source: USN-8910-1, Ubuntu Security Notices.

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.