Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 9 libxml2 Critical Security Flaw Denial of Service MGASA-2026-0027

mageia
Calendar Grey January 30, 2026
Dist Mageia Esm H88
Mageia recently patched libxml2 to address multiple vulnerabilities, including denial of service and stack overflow issues.
MGASA-2026-0027 - Updated libxml2 packages fix security vulnerabilities

Summary

Description: xmlcatalog xmlParseSGMLCatalog recursion. (CVE-2025-8732) Unbounded relaxng include recursion leading to stack overflow. (CVE-2026-0989) Denial of service via uncontrolled recursion in xml catalog processing. (CVE-2026-0990) Denial of service via crafted xml catalogs. (CVE-2026-0992)

References

- https://bugs.mageia.org/show_bug.cgi?id=35058

- https://ubuntu.com/security/notices/USN-7974-1

- https://www.cve.org/CVERecord?id=CVE-2025-8732

- https://www.cve.org/CVERecord?id=CVE-2026-0989

- https://www.cve.org/CVERecord?id=CVE-2026-0990

- https://www.cve.org/CVERecord?id=CVE-2026-0992

Resolution

SRPMS

- 9/core/libxml2-2.10.4-1.9.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 30 Jan 2026
URL: https://advisories.mageia.org/MGASA-2026-0027.html
Type: security
CVE: CVE-2025-8732, CVE-2026-0989, CVE-2026-0990, CVE-2026-0992

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here