USN-7467-2: libxml2 vulnerabilities
USN-7467-1 fixed several vulnerabilities in libxml2. This update provides the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: It was discovered that the libxml2 Python bindings incorrectly handled certain return values. An attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service. (CVE-2025-32414) It was discovered that libxml2 incorrectly handled certain memory operations. A remote attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service. (CVE-2025-32415)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7467-2?
USN-7467-2 addresses vulnerabilities in libxml2 that may allow for potential attacks through incorrectly handled return values.
How do I fix USN-7467-2?
To mitigate the vulnerabilities addressed in USN-7467-2, upgrade libxml2 and its related Python packages to the specified remedied version.
Which Ubuntu versions are affected by USN-7467-2?
USN-7467-2 affects Ubuntu 16.04 LTS and Ubuntu 18.04 LTS with specific versions of libxml2 and its Python bindings.
What packages are impacted by USN-7467-2?
The impacted packages include libxml2, python-libxml2, and python3-libxml2 in the specified vulnerable versions.
Is there any prior notification related to USN-7467-2?
Yes, USN-7467-1 provided initial information about the vulnerabilities that USN-7467-2 updates.