CVE-2015-8866: Canonical Ubuntu Linux
Critical severity, CVSS 9.6. EPSS: 4.2% chance of exploitation in the next 30 days.
ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.2 only
- PHP PHP: from 5.5.0, before 5.5.22 (fixed in 5.5.22); from 5.6.0, before 5.6.6 (fixed in 5.6.6); from 7.0.0, before 7.0.27 (fixed in 7.0.27); from 7.1.0, before 7.1.13 (fixed in 7.1.13); from 7.2.0, before 7.2.1 (fixed in 7.2.1)
- Suse Linux Enterprise Module For Web Scripting: version 12 only
- Suse Linux Enterprise Software Development Kit: version 12 only
Published 2016-05-22. Last modified 2026-06-17.