|
|
Log in / Subscribe / Register

Ubuntu alert USN-7852-2 (libxml2)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-7852-2] libxml2 vulnerability
Date:  Thu, 27 Nov 2025 15:31:23 +0000
Message-ID:  <E1vOdxr-0003FM-2o@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-7852-2 November 27, 2025 libxml2 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: libxml2 could be made to crash or run programs if it opened a specially crafted file. Software Description: - libxml2: GNOME XML library Details: USN-7582-1 fixed a vulnerability in libxml2. This update provides the corresponding fix for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. Original advisory details: It was discovered that libxslt, used by libxml2, incorrectly handled certain attributes. An attacker could use this issue to cause a crash, resulting in a denial of service, or possibly execute arbitrary code. This update adds a fix to libxml2 to mitigate the libxslt vulnerability. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS libxml2 2.9.10+dfsg-5ubuntu0.20.04.10+esm3 Available with Ubuntu Pro python-libxml2 2.9.10+dfsg-5ubuntu0.20.04.10+esm3 Available with Ubuntu Pro python3-libxml2 2.9.10+dfsg-5ubuntu0.20.04.10+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS libxml2 2.9.4+dfsg1-6.1ubuntu1.9+esm6 Available with Ubuntu Pro python-libxml2 2.9.4+dfsg1-6.1ubuntu1.9+esm6 Available with Ubuntu Pro python3-libxml2 2.9.4+dfsg1-6.1ubuntu1.9+esm6 Available with Ubuntu Pro Ubuntu 16.04 LTS libxml2 2.9.3+dfsg1-1ubuntu0.7+esm11 Available with Ubuntu Pro python-libxml2 2.9.3+dfsg1-1ubuntu0.7+esm11 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7852-2 https://ubuntu.com/security/notices/USN-7852-1 CVE-2025-7425


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmkobZ4ACgkQcpJm3tlz hgE3Hg//VvaozKwusitOo2SR/R3QMgnUVd01/jULPdHOa/hYdItQ3qNVU25UVOu0 knwmwJLE6fPTTD8wQPDpAjPBKycbrRZFPyXM3zn29IWZ+16DjhdVBpymD85TGI2h 2ly8iB7fDvxXJohC7TN76Awskh1BwX4nsO28zFP/J6CfuUGAB+G9VKS07suBygII njWIg4HnaVHzSUeHsCj31H0b/cW5y5y4VEWnVlqjnWKMRKrfm2rcsK7sxYlEuNZZ TIwMSsxmZapJWcxLZKLLWXWzfEzIE0o+Hds/ZEsi0rFnFoPMGlUfuNPelz8/xus1 NF/5mlZA6iYT5+ayRoN2g4xN5Xt5Y5UGRAe+M1bBegpAJ0c/abtcYIEbVfv6AOfK MmFpri50K7GFFALeKqR4k2SAg85xt/dj973/PruxajCsNoZ90zvzPUmB23jxREjo u9gwvkiSBtKWoZPfEK/jQs9Rf+wxtp0RLSF8ba3iDzpN54DNiWfQNz5r0J1ylh76 aS5CXyCY+3F8iiEy2QOK/vlz5Yl1uVjqclGQOZ5aBuHbQqAbTBcWvlK+GVRjDQKQ +kj8XJqpAhW228HYUWtNkQZ/PVKOFcUvH1w4pItBTbd177Y9pXIGb+hxhlPh/d+9 Cmy+axSvQ2NcEqTFqzOSEIlsrK4iEC02VpFDzPgPuUS1CVqT4Lg= =l4Ea -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds