Ubuntu USN-8910-1: six libxml2 flaws, XInclude ignored no-network option
Canonical published USN-8910-1 on 8 October, fixing six vulnerabilities in libxml2, the GNOME XML library that sits underneath a large share of Linux software — from language bindings such as Python's lxml and PHP's XML extensions to desktop and server tools. Fixed packages exist for Ubuntu 26.04, 24.04, 22.04 LTS, and through Ubuntu Pro for 20.04, 18.04, 16.04 and 14.04.
The six issues, in Canonical's words:
- CVE-2026-86144 — XInclude ignored parser options. libxml2 did not apply options such as disabling network access when processing XInclude directives in some cases. Canonical names the consequences: XML external entity injection, server-side request forgery or denial of service. This is the one to read twice: code that deliberately turned network access off was relying on a promise that did not hold for XInclude.
- CVE-2026-86138 — heap overflow on large qualified names (crash, possibly code execution).
- CVE-2026-86142 — heap overflow on large XPointer expressions (crash, possibly code execution), found by Xudong Cao and Meng Xu.
- CVE-2026-86143 — integer overflow before output lengths were passed to write callbacks (crash), same researchers.
- CVE-2026-76781 — crafted XML catalog could crash libxml2, found by Yirou Yang.
- CVE-2026-86139 — escaping very large URI strings used excessive resources; only 26.04 LTS was affected.

Fixed versions listed in the notice include 2.15.2+dfsg-0.1ubuntu0.3 (26.04, package libxml2-16), 2.9.14+dfsg-1.3ubuntu3.10 (24.04) and 2.9.13+dfsg-1ubuntu0.14 (22.04).
What to do. A standard system update applies the fix, but long-running processes keep the old library in memory until they restart — web servers, application servers and workers that parse XML need a restart after the upgrade. Containers built on an affected base image need a rebuild, not just a host update. And if your application parses untrusted XML with XInclude enabled, treat the "network disabled" setting as unverified on any unpatched build and check whether XInclude needs to be on at all.
Source: Ubuntu Security Notice USN-8910-1, "libxml2 vulnerabilities", 8 October 2026 — https://ubuntu.com/security/notices/USN-8910-1