CVE-2015-8866: Canonical Ubuntu Linux

Critical severity, CVSS 9.6. EPSS: 4.2% chance of exploitation in the next 30 days.

ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only
  • Opensuse Leap: version 42.1 only
  • Opensuse Opensuse: version 13.2 only
  • PHP PHP: from 5.5.0, before 5.5.22 (fixed in 5.5.22); from 5.6.0, before 5.6.6 (fixed in 5.6.6); from 7.0.0, before 7.0.27 (fixed in 7.0.27); from 7.1.0, before 7.1.13 (fixed in 7.1.13); from 7.2.0, before 7.2.1 (fixed in 7.2.1)
  • Suse Linux Enterprise Module For Web Scripting: version 12 only
  • Suse Linux Enterprise Software Development Kit: version 12 only

Published 2016-05-22. Last modified 2026-06-17.