INFSA-2025:2686: libxml2 security update

Information about definition

Identificator: INFSA-2025:2686

Type: security

Release date: 2025-03-17 17:11:04 UTC

Information about package

The libxml2 library is a development toolbox providing the implementation of various XML standards.

Vulnerabilities description

  • CVE-2024-56171

    libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.

  • CVE-2025-24928

    libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 8.1 no information
no information 7.8 no information
Critical, important, moderate, low

Updated packages

loader icon Preparing to download...
Architecture: Download