Ubuntu alert USN-8460-1 (libxml2)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8460-1] libxml2 vulnerabilities | |
| Date: | Mon, 22 Jun 2026 21:19:56 +0000 | |
| Message-ID: | <E1wbm3g-0005qO-KK@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8460-1 June 22, 2026 libxml2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 Summary: Several security issues were fixed in libxml2. Software Description: - libxml2: GNOME XML library Details: It was discovered that libxml2 did not properly release memory allocated in the xmllint utility. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-1757) A type confusion vulnerability was found in libxml2 when processing a specially crafted XML document. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-6732) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libxml2-16 2.15.2+dfsg-0.1ubuntu0.1 libxml2-dev 2.15.2+dfsg-0.1ubuntu0.1 libxml2-source 2.15.2+dfsg-0.1ubuntu0.1 libxml2-utils 2.15.2+dfsg-0.1ubuntu0.1 python3-libxml2 2.15.2+dfsg-0.1ubuntu0.1 Ubuntu 25.10 libxml2-16 2.14.5+dfsg-0.2ubuntu0.2 libxml2-dev 2.14.5+dfsg-0.2ubuntu0.2 libxml2-utils 2.14.5+dfsg-0.2ubuntu0.2 python3-libxml2 2.14.5+dfsg-0.2ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8460-1 CVE-2026-1757, CVE-2026-6732 Package Information: https://launchpad.net/ubuntu/+source/libxml2/2.15.2+dfsg-... https://launchpad.net/ubuntu/+source/libxml2/2.14.5+dfsg-...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmo5pswACgkQcpJm3tlz hgG3xQ//YDX3bxOW79pIMmRPqmNDwo9nDYYz6HhfwiDSiBX0zeRjAdXlOcbYuHaV KFzHccN9szGdYish+rDP+QGasduGzgez9FmiuTwh90P1530PuuiwEHGpBm8vu2sH OWlBWCtIBFmRmrCxGSh6StXLnOAaag1+AdGI8/FQlkwm1YSDdVpN+HtDrOjILhV3 34CbinzGFqfgESDcMarspH4jwhqjOWmWiTp6n+rJqKp8M5l9d2APipwNiO7pLuVE bI2kcDHNf0Bt8edP8U4bO267l/SebO9DhgAvw25WftEmjgmvPQadtdnsf/uZXeEU H+QQ6zjKEATwd+sqQbNHjXpv2fDCTnk44dQxy/PO07weSYHbRjRBZh9hZPmB3vxW jbvwqTcNEmZWgKpxNCm/c57p/03bbw4LtwVlokKL31pwrnskX3n2jvxRAjn6ty54 g470D6/qMwpZqD0AZC8DNgislcrX1RVKAiNNc2Bi8an8fhmIadlAyrGuaQy71fKa MkvXEJLkHIxqwSgXT2uodZl0k+Gk7K4RS3JTZiYXhR/AdmAQE/QiEuCJsrwIhKSu CiiMmaQmpMZZ3pcswtpOMOLbaMl+gUtJwBGfaLbH8cjHjHtVvJngOWfFOskUZFUA 77XM5GDziJD3loUZu+AyHKPsvVolDUu68+JnC8CMhDSncU07Evg= =yvd2 -----END PGP SIGNATURE-----
