INFSA-2025:10699: libxml2 security update

Information about definition

Identificator: INFSA-2025:10699

Type: security

Release date: 2025-07-25 10:15:25 UTC

Information about package

The libxml2 library is a development toolbox providing the implementation of various XML standards.

Vulnerabilities description

  • CVE-2025-49794

    A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.

  • CVE-2025-49796

    A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.

  • CVE-2025-6021

    A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 9.1 no information
no information 9.1 no information
NIST — CVE-2025-6021
no information 7.5 no information
Critical, important, moderate, low

Updated packages