USN-7852-1: libxml2 vulnerability
USN-7852-1: libxml2 vulnerability
Publication date :30 October 2025
Overview : libxml2 could be made to crash or run programs if it opened a specially crafted file.Publication date
Packages
- libxml2 - GNOME XML library
Details
It was discovered that libxslt, used by libxml2, incorrectly handled
certain attributes. An attacker could use this issue to cause a crash,
resulting in a denial of service, or possibly execute arbitrary code. This
update adds a fix to libxml2 to mitigate the libxslt vulnerability.
Update instructions
The problem can be corrected by updating your system to the following package versions:
25.04 plucky
- libxml2 – 2.12.7+dfsg+really2.9.14-0.4ubuntu0.4
- python3-libxml2 – 2.12.7+dfsg+really2.9.14-0.4ubuntu0.4
24.04 LTS noble - libxml2 – 2.9.14+dfsg-1.3ubuntu3.6
- python3-libxml2 – 2.9.14+dfsg-1.3ubuntu3.6
22.04 LTS jammy - libxml2 – 2.9.13+dfsg-1ubuntu0.10
- python3-libxml2 – 2.9.13+dfsg-1ubuntu0.10

