CVE-2016-3627: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 7% chance of exploitation in the next 30 days.

The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML document.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
  • Debian Debian Linux: version 8.0 only
  • HP Icewall Federation Agent: version 3.0 only
  • HP Icewall File Manager: version 3.0 only
  • Opensuse Leap: version 42.1 only
  • Oracle Solaris: version 11.3 only
  • Oracle Vm Server: version 3.3 only; version 3.4 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Eus: version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.2 only; version 7.4 only; version 7.6 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
  • Red Hat JBoss Core Services: affected versions not specified
  • Xmlsoft LIBXML2: up to and including 2.9.3

Published 2016-05-17. Last modified 2026-06-17.