Advisory USN-8910-1, published on 8 October 2026 in the Ubuntu Security feed, describes six vulnerabilities in libxml2, an XML processing library. According to the text, the library incorrectly handled certain XML catalogs, large qualified names, large URI strings, large XPointer expressions and XInclude directives, and did not check for integer overflows before passing output lengths to write callbacks. The identifiers are CVE-2026-76781, CVE-2026-86138, CVE-2026-86139, CVE-2026-86142, CVE-2026-86143 and CVE-2026-86144. The described impacts include denial of service, arbitrary code execution in some cases, XML external entity injection and server-side request forgery. The text credits Yirou Yang, Xudong Cao and Meng Xu with the discoveries. The URI escaping flaw causes excessive resource consumption and affects only Ubuntu 26.04 LTS. To confirm affected versions and fixes, consult the official Ubuntu Security advisory under the number USN-8910-1 on Ubuntu's own website. This item's source text is a machine translation of the feed, so verify the details in the advisory before acting.
Cyber ·
USN-8910-1: libxml2 vulnerabilities with denial of service, code execution, XXE and SSRF
Ubuntu Security advisory on six libxml2 flaws that may lead to denial of service, code execution, XXE injection and SSRF. One of them affects only Ubuntu 26.04 LTS.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.