USN-8910-1: libxml2 vulnerabilities
Ubuntu patched libxml2 flaws, including a heap overflow that could crash the library or allow code execution.
Canonical published USN-8910-1 covering multiple libxml2 flaws. CVE-2026-76781, discovered by Yirou Yang, involves mishandled XML catalogs that can crash the library and cause a denial of service. CVE-2026-86138 is a heap-based buffer overflow in large qualified names that could crash libxml2 or possibly allow arbitrary code execution. The notice also describes unsafe escaping of large URI strings, but the provided text is cut off before any further CVE identifier. No exploitation is reported.
- CVE-2026-76781: crafted XML catalogs can crash libxml2.
- CVE-2026-86138: heap overflow on large names may allow code execution.
- A URI-escaping flaw is described; the excerpt does not name its CVE.
- The Ubuntu notice does not report active exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-767815.5—NULL pointer dereference DoS in libxml2 XML catalogspublished · libxml2 project (GNOME/xmlsoft; packaged by distributors including Red Hat and U libxml2
- CVE-2026-861387.8<1%Heap Buffer Overflow via Integer Overflow in libxml2 before 2.15.4published · libxml2 (upstream project) libxml2
Yirou Yang discovered that libxml2 incorrectly handled certain XML catalogs. If a user or automated system was tricked into processing a specially crafted XML catalog, an attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service. (CVE-2026-76781) It was discovered that libxml2 incorrectly handled certain large qualified names, leading to a heap-based buffer overflow. An attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-86138) It was discovered that libxml2 incorrectly handled escaping certain large URI strings. An attacker could possibly use this issue to…
This source does not provide full text. Read it at ubuntu.com.