Ubuntu libxml2 Updates Fix Six Vulnerabilities

P2 — VALIDATE AND UPDATENot provided by the authority · Not provided by the authorityEXPLOITATION: NOT STATED

Quick Answer

The authority published USN-8910-1 for libxml2 on Ubuntu 26.04 LTS (resolute), Ubuntu 24.04 LTS (noble), Ubuntu 22.04 LTS (jammy), Ubuntu 20.04 ESM (focal), Ubuntu 18.04 ESM (bionic), Ubuntu 16.04 ESM (xenial), Ubuntu 14.04 ESM (trusty). Several security issues were fixed in libxml2. Yirou Yang discovered that libxml2 incorrectly handled certain XML catalogs. If a user or automated system was tricked into processing a specially crafted XML catalog, an attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service. (CVE-2026-76781) It was discovered that libxml2 incorrectly handled certain large qualified names, leading to a heap-based buffer overflow. An attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-86138) It was discovered that libxml2 incorrectly handled escaping certain large URI strings. An attacker could possibly use this issue to cause libxml2 to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-86139) Xudong Cao and Meng Xu discovered that libxml2 incorrectly handled certain large XPointer expressions, leading to a heap-based buffer overflow. An attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-86142) Xudong Cao and Meng Xu discovered that libxml2 did not check for integer overflows before passing output lengths to write callbacks. An attacker could possibly use this issue to cause an application using libxml2 to crash, resulting in a denial of service. (CVE-2026-86143) It was discovered that libxml2 did not apply parser options, such as disabling network access, when processing XInclude directives under certain circumstances. An attacker could possibly use this issue to perform XML external entity injection or server-side request forgery attacks, or cause a denial of service. (CVE-2026-86144) In general, a standard system update will make all the necessary changes. Affected deployments should be matched to the authority's exact scope and moved to the supported fixed release.

Confirm Scope And Apply The Supported Fix

What to do now: Inventory libxml2 on Ubuntu 26.04 LTS (resolute), Ubuntu 24.04 LTS (noble), Ubuntu 22.04 LTS (jammy), Ubuntu 20.04 ESM (focal), Ubuntu 18.04 ESM (bionic), Ubuntu 16.04 ESM (xenial), Ubuntu 14.04 ESM (trusty), match the exact affected release or feature, apply the authority-supported fixed build or service remediation, validate the dependent workflow, and preserve evidence.

Open the authoritative advisory

Last verified: 2026-10-09 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopelibxml2 on Ubuntu 26.04 LTS (resolute), Ubuntu 24.04 LTS (noble), Ubuntu 22.04 LTS (jammy), Ubuntu 20.04 ESM (focal), Ubuntu 18.04 ESM (bionic), Ubuntu 16.04 ESM (xenial), Ubuntu 14.04 ESM (trusty)
AdvisoryUSN-8910-1
CVEsCVE-2026-76781, CVE-2026-86138, CVE-2026-86139, CVE-2026-86142, CVE-2026-86143, CVE-2026-86144
Authoritative release date2026-10-08 20:05:15.103786 UTC
Authority revision date2026-10-08 20:05:15.103786 UTC
Affected versionsThe Ubuntu releases and source packages enumerated by USN-8910-1: Ubuntu 26.04 LTS (resolute), Ubuntu 24.04 LTS (noble), Ubuntu 22.04 LTS (jammy), Ubuntu 20.04 ESM (focal), Ubuntu 18.04 ESM (bionic), Ubuntu 16.04 ESM (xenial), Ubuntu 14.04 ESM (trusty).
Fixed versionbionic: libxml2 2.9.4+dfsg1-6.1ubuntu1.9+esm9 / focal: libxml2 2.9.10+dfsg-5ubuntu0.20.04.10+esm6 / jammy: libxml2 2.9.13+dfsg-1ubuntu0.14 / noble: libxml2 2.9.14+dfsg-1.3ubuntu3.10 / resolute: libxml2 2.15.2+dfsg-0.1ubuntu0.3 / trusty: libxml2 2.9.1+dfsg1-3ubuntu4.13+esm13 / xenial: libxml2 2.9.3+dfsg1-1ubuntu0.7+esm14
CVSS base scoreNot provided by the authority
CVSS severityNot provided by the authority
Exploitation statusNot stated by the authority; no exploitation claim is inferred.

What Changed

Several security issues were fixed in libxml2. Yirou Yang discovered that libxml2 incorrectly handled certain XML catalogs. If a user or automated system was tricked into processing a specially crafted XML catalog, an attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service. (CVE-2026-76781) It was discovered that libxml2 incorrectly handled certain large qualified names, leading to a heap-based buffer overflow. An attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-86138) It was discovered that libxml2 incorrectly handled escaping certain large URI strings. An attacker could possibly use this issue to cause libxml2 to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-86139) Xudong Cao and Meng Xu discovered that libxml2 incorrectly handled certain large XPointer expressions, leading to a heap-based buffer overflow. An attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-86142) Xudong Cao and Meng Xu discovered that libxml2 did not check for integer overflows before passing output lengths to write callbacks. An attacker could possibly use this issue to cause an application using libxml2 to crash, resulting in a denial of service. (CVE-2026-86143) It was discovered that libxml2 did not apply parser options, such as disabling network access, when processing XInclude directives under certain circumstances. An attacker could possibly use this issue to perform XML external entity injection or server-side request forgery attacks, or cause a denial of service. (CVE-2026-86144) In general, a standard system update will make all the necessary changes.

What To Validate Now

  1. Inventory. Locate libxml2 on Ubuntu 26.04 LTS (resolute), Ubuntu 24.04 LTS (noble), Ubuntu 22.04 LTS (jammy), Ubuntu 20.04 ESM (focal), Ubuntu 18.04 ESM (bionic), Ubuntu 16.04 ESM (xenial), Ubuntu 14.04 ESM (trusty) deployments, versions, enabled features, exposure paths, owners, and dependent services.
  2. Establish applicability. Compare each deployment with the authority's affected-version statement: The Ubuntu releases and source packages enumerated by USN-8910-1: Ubuntu 26.04 LTS (resolute), Ubuntu 24.04 LTS (noble), Ubuntu 22.04 LTS (jammy), Ubuntu 20.04 ESM (focal), Ubuntu 18.04 ESM (bionic), Ubuntu 16.04 ESM (xenial), Ubuntu 14.04 ESM (trusty). Do not infer applicability from product family or severity alone.
  3. Remediate. Apply bionic: libxml2 2.9.4+dfsg1-6.1ubuntu1.9+esm9 / focal: libxml2 2.9.10+dfsg-5ubuntu0.20.04.10+esm6 / jammy: libxml2 2.9.13+dfsg-1ubuntu0.14 / noble: libxml2 2.9.14+dfsg-1.3ubuntu3.10 / resolute: libxml2 2.15.2+dfsg-0.1ubuntu0.3 / trusty: libxml2 2.9.1+dfsg1-3ubuntu4.13+esm13 / xenial: libxml2 2.9.3+dfsg1-1ubuntu0.7+esm14 through the supported vendor or project channel, following the current advisory and change-control requirements.
  4. Validate. Confirm the resulting version or managed-service state, exercise representative functionality and recovery paths, monitor for regressions, and document exceptions.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Treat untrusted XML as hostile and test catalogs, XInclude, XPointer, URI escaping, network-access restrictions, and dependent parsers after updating. Preserve package-manager output, before-and-after source-package versions, validation results, and rollback evidence.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.