UbuntuUpdates.org

Package "libxml2"

Name: libxml2

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • GNOME XML library - source code
  • GNOME XML library - Python3 bindings

Latest version: 2.15.2+dfsg-0.1ubuntu0.2
Release: resolute (26.04)
Level: security
Repository: universe

Links



Other versions of "libxml2" in Resolute

Repository Area Version
base main 2.15.2+dfsg-0.1
base universe 2.15.2+dfsg-0.1
security main 2.15.2+dfsg-0.1ubuntu0.2
updates main 2.15.2+dfsg-0.1ubuntu0.1
updates universe 2.15.2+dfsg-0.1ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2.15.2+dfsg-0.1ubuntu0.2 2026-09-21 13:07:37 UTC

libxml2 (2.15.2+dfsg-0.1ubuntu0.2) resolute-security; urgency=medium

  * SECURITY UPDATE: stack-based buffer overflow in xmlSnprintfElements
    - debian/patches/CVE-2026-86140.patch: fix: add bounds checks to
      xmlSnprintfElements in valid.c in valid.c.
    - CVE-2026-86140
  * SECURITY UPDATE: double free in Python SAX attributeDecl callback
    - debian/patches/CVE-2026-74860.patch: python: Do not decref string after
      adding to the list in python/libxml.c.
    - CVE-2026-74860

 -- John Breton Thu, 17 Sep 2026 08:09:57 -0400

Source diff to previous version
CVE-2026-86140 In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
CVE-2026-74860 A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML doc

Version: 2.15.2+dfsg-0.1ubuntu0.1 2026-06-22 19:07:55 UTC

  libxml2 (2.15.2+dfsg-0.1ubuntu0.1) resolute-security; urgency=medium

  * SECURITY UPDATE: Denial of service in parser.
    - debian/patches/CVE-2026-6732.patch: Pass userData instead of ctxt in
      parser.c
    - CVE-2026-6732

 -- Kyle Kernick <email address hidden> Fri, 19 Jun 2026 11:43:10 -0600

CVE-2026-6732 A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document



About   -   Send Feedback to @ubuntu_updates