RHSA-2025:10630HighCVSS 9.1
Red Hat Security Advisory: libxml2 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2025-6021 — libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 CVE-2025-49794 — libxml: Heap use after free (UAF) leads to Denial of service (DoS) CVE-2025-49795 — libxml: Null pointer dereference leads to Denial of service (DoS) CVE-2025-49796 — libxml: Type confusion leads to Denial of service (DoS)
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2025:10630
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2372373
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2372379
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2372385
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2372406
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_10630.json