RHSA-2025:12199HighCVSS 9.1
Red Hat Security Advisory: libxml2 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-6021 — libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 CVE-2025-49794 — libxml: Heap use after free (UAF) leads to Denial of service (DoS) CVE-2025-49796 — libxml: Type confusion leads to Denial of service (DoS)
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2025:12199
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2372373
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2372385
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2372406
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_12199.json