UBUNTU-CVE-2026-1757

Source
https://ubuntu.com/security/CVE-2026-1757
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-1757.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-1757
Upstream
Published
2026-02-02T13:15:00Z
Modified
2026-02-23T07:09:10.296827Z
Severity
  • 6.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • Ubuntu - low
Summary
[none]
Details

A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.

References

Affected packages

Ubuntu:25.10 / libxml2

Package

Name
libxml2
Purl
pkg:deb/ubuntu/libxml2@2.14.5+dfsg-0.2ubuntu0.1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.12.7+dfsg+really2.9.14-0.4
2.12.7+dfsg+really2.9.14-0.4ubuntu0.1
2.12.7+dfsg+really2.9.14-1
2.14.3+dfsg-0exp1
2.14.3+dfsg-0exp2
2.14.3+dfsg-0exp3
2.14.4+dfsg-0exp1
2.14.5+dfsg-0exp1
2.14.5+dfsg-0exp2
2.14.5+dfsg-0.1
2.14.5+dfsg-0.2
2.14.5+dfsg-0.2ubuntu0.1

Ecosystem specific

{
    "priority_reason": "Memory leak in command line tool",
    "binaries": [
        {
            "binary_name": "libxml2-16",
            "binary_version": "2.14.5+dfsg-0.2ubuntu0.1"
        },
        {
            "binary_name": "libxml2-dev",
            "binary_version": "2.14.5+dfsg-0.2ubuntu0.1"
        },
        {
            "binary_name": "libxml2-utils",
            "binary_version": "2.14.5+dfsg-0.2ubuntu0.1"
        },
        {
            "binary_name": "python3-libxml2",
            "binary_version": "2.14.5+dfsg-0.2ubuntu0.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-1757.json"