USN-8787-1: libxml2 vulnerabilities
Ubuntu patched libxml2 flaws that could crash the library, enable code execution, or cause denial of service.
Ubuntu security notice USN-8787-1 covers two libxml2 vulnerabilities. CVE-2026-86140 involves incorrect handling of certain XML elements that could crash libxml2 or allow arbitrary code execution. CVE-2026-74860 affects XML document handling through Python bindings and could let a remote attacker crash applications, causing a denial of service. The notice does not say either flaw is being exploited.
- CVE-2026-86140 may crash libxml2 or allow arbitrary code execution.
- CVE-2026-74860 can crash applications using the Python bindings.
- Fixes are published in Ubuntu notice USN-8787-1.
- The notice does not report active exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-748608.5<1%Double-free DoS in libxml2 Python bindings via crafted DTD attribute declarationspublished · libxml2 (GNOME project); distributed in vendor packages tracked by Red Hat and o libxml2 with Python bindings enabled (libxml2-python / distro Python bindings), SAX parsing path
- CVE-2026-861407.8<1%
It was discovered that libxml2 incorrectly handled certain XML elements under certain circumstances. An attacker could possibly use this issue to cause libxml2 to crash or execute arbitrary code. (CVE-2026-86140) It was discovered that libxml2 incorrectly handled certain XML documents when used with Python bindings. A remote attacker could possibly use this issue to cause applications using libxml2 to crash, resulting in a denial of service. (CVE-2026-74860)
This source does not provide full text. Read it at ubuntu.com.