7.5highHigh
CVE-2025-6021
Xmlsoft Libxml2
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
Exploitation status
- Published references include exploit or proof-of-concept material. There is no confirmation it is being used in real attacks.
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, no account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 7.5 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Weakness
- CWE-787
- Assigned by
- secalert@redhat.com
Dates
- Published
- 2025-06-12
- Last modified
- 2026-09-01
- Sources
- NVD
Affected products
- Xmlsoft Libxml2- 2.14.4
- Redhat Jboss Core Servicesall versions
- Redhat Openshift Container Platform4.12, 4.13, 4.14, 4.15, 4.16, 4.17, 4.18
- Redhat Openshift Container Platform For Arm644.13, 4.14, 4.15, 4.16, 4.17, 4.18
- Redhat Openshift Container Platform For Ibm Z4.13, 4.14, 4.15, 4.16, 4.17, 4.18
- Redhat Openshift Container Platform For Linuxone4.13, 4.14, 4.15, 4.16, 4.17, 4.18
- Redhat Openshift Container Platform For Power4.13, 4.14, 4.15, 4.16, 4.17, 4.18
- Redhat Enterprise Linux8.0, 9.0, 10.0
- Redhat Enterprise Linux Eus8.4, 8.6, 8.8, 9.4, 9.6, 10.0
- Redhat Enterprise Linux For Arm 648.0 aarch64, 9.0 aarch64, 9.4 aarch64, 10.0 aarch64
- Redhat Enterprise Linux For Arm 64 Eus9.4 aarch64, 9.6 aarch64, 10.0 aarch64
- Redhat Enterprise Linux For Ibm Z Systems8.0 s390x, 9.4 s390x, 10.0 s390x
As listed in the NVD configuration data. Not a statement about your estate.
References
- https://access.redhat.com/errata/RHSA-2025:10630
- https://access.redhat.com/errata/RHSA-2025:10698
- https://access.redhat.com/errata/RHSA-2025:10699
- https://access.redhat.com/errata/RHSA-2025:11580
- https://access.redhat.com/errata/RHSA-2025:11673
- https://access.redhat.com/errata/RHSA-2025:12098
- https://access.redhat.com/errata/RHSA-2025:12099
- https://access.redhat.com/errata/RHSA-2025:12199
- https://access.redhat.com/errata/RHSA-2025:12237
- https://access.redhat.com/errata/RHSA-2025:12239
- https://access.redhat.com/errata/RHSA-2025:12240
- https://access.redhat.com/errata/RHSA-2025:12241
- https://access.redhat.com/errata/RHSA-2025:13267
- https://access.redhat.com/errata/RHSA-2025:13289
- https://access.redhat.com/errata/RHSA-2025:13325