Several security issues were fixed in the xmltok library.. ========================================================================== Ubuntu Security Notice USN-8023-1 February 11, 2026 libxmltok vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in the xmltok library. Software Description: - libxmltok: XML Parser Toolkit, runtime libraries Details: It was discovered that Expat, contained within the xmltok library, incorrectly handled the initialization of parsers for external entities. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-24515) It was discovered that Expat, contained within the xmltok library, incorrectly handled integer calculations when allocating memory for XML tags. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-25210) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libxmltok1t64 1.2-4.1ubuntu2.24.0.4.1+esm4 Available with Ubuntu Pro Ubuntu 22.04 LTS libxmltok1 1.2-4ubuntu0.22.04.1~esm6 Available with Ubuntu Pro Ubuntu 20.04 LTS libxmltok1 1.2-4ubuntu0.20.04.1~esm6 Available with Ubuntu Pro Ubuntu 18.04 LTS libxmltok1 1.2-4ubuntu0.18.04.1~esm6 Available with Ubuntu Pro Ubuntu 16.04 LTS libxmltok1 1.2-3ubuntu0.16.04.1~esm5 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8023-1 CVE-2026-24515, CVE-2026-25210 . Several security issues in xmltok library affect Ubuntu users. Recommendations provided for updates to ensure protection.. xmltok security fix, Ubuntu library update, Denial of Service threat, xmltok vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Libxmltok could be made to crash if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-7307-1 February 26, 2025 libxmltok vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Libxmltok could be made to crash if it opened a specially crafted file. Software Description: - libxmltok: XML Parser Toolkit, developer libraries Details: Tim Boddy discovered that Expat, contained within the xmltok library, did not properly handle memory reallocation when processing XML files. If a user or application linked against Expat were tricked into opening a crafted XML file, an attacker could cause a denial of service by consuming excessive memory resources. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 libxmltok1t64 1.2-4.1ubuntu3.2 Ubuntu 24.04 LTS libxmltok1t64 1.2-4.1ubuntu2.24.0.4.1+esm3 Available with Ubuntu Pro Ubuntu 22.04 LTS libxmltok1 1.2-4ubuntu0.22.04.1~esm5 Available with Ubuntu Pro Ubuntu 20.04 LTS libxmltok1 1.2-4ubuntu0.20.04.1~esm5 Available with Ubuntu Pro Ubuntu 18.04 LTS libxmltok1 1.2-4ubuntu0.18.04.1~esm5 Available with Ubuntu Pro In general, a standard system update will make all thenecessary changes. References: https://ubuntu.com/security/notices/USN-7307-1 CVE-2012-1148 Package Information: https://launchpad.net/ubuntu/+source/libxmltok/1.2-4.1ubuntu3.2 . Ubuntu Security Advisory USN-7308-1 discusses vulnerabilities in libcurl that may expose systems to remote code execution risks.. libxmltok, denial of service, memory issues, Ubuntu updates, security advisory. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in libxmltok.. ========================================================================== Ubuntu Security Notice USN-7001-2 September 17, 2024 libxmltok vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in libxmltok. Software Description: - libxmltok: XML Parser Toolkit, developer libraries Details: USN-7001-1 fixed vulnerabilities in xmltol library. This update provides the corresponding updates for Ubuntu 24.04 LTS. Original advisory details: Shang-Hung Wan discovered that Expat, contained within the xmltok library, did not properly handle certain function calls when a negative input length was provided. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2024-45490) Shang-Hung Wan discovered that Expat, contained within the xmltok library, did not properly handle the potential for an integer overflow on 32-bit platforms. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2024-45491) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libxmltok1t64 1.2-4.1ubuntu2.24.0.4.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7001-2 https://ubuntu.com/security/notices/USN-7001-1 CVE-2024-45490, CVE-2024-45491 . Ubuntu Security Advisory USN-7001-2 provides critical updates for libxmltok to address significant vulnerabilities impacting Ubuntu 24.04 LTS.. libxmltok vulnerabilities, Ubuntu security updates, XML parsertoolkit. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in libxmltok.. ========================================================================== Ubuntu Security Notice USN-7001-1 September 12, 2024 libxmltok vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in libxmltok. Software Description: - libxmltok: XML Parser Toolkit, runtime libraries Details: Shang-Hung Wan discovered that Expat, contained within the xmltok library, did not properly handle certain function calls when a negative input length was provided. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2024-45490) Shang-Hung Wan discovered that Expat, contained within the xmltok library, did properly handle the potential for an integer overflow on 32-bit platforms. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2024-45491) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS libxmltok1 1.2-4ubuntu0.22.04.1~esm3 Available with Ubuntu Pro Ubuntu 20.04 LTS libxmltok1 1.2-4ubuntu0.20.04.1~esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS libxmltok1 1.2-4ubuntu0.18.04.1~esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS libxmltok1 1.2-3ubuntu0.16.04.1~esm4 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7001-1 CVE-2024-45490, CVE-2024-45491 . Vulnerabilities in libxmltok have been patched for Ubuntu versions 16.04 through 22.04, mitigating risks related to Denial of Service (DoS) and potential arbitrary code execution.. libxmltok Security, DoS Issues, Ubuntu Update. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.