Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2
Published Jun 12, 2025
7.5
HIGHCVSS 3.1
EPSS 1.37%
Description
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | affected |
|
Configuration 2
- n/a
- 4.12
- 4.13
- 4.14
- 4.15
- 4.16
- 4.17
- 4.18
- 4.13
- 4.14
- 4.15
- 4.16
- 4.17
- 4.18
- 4.13
- 4.14
- 4.15
- 4.16
- 4.17
- 4.18
- 4.13
- 4.14
- 4.15
- 4.16
- 4.17
- 4.18
- 4.13
- 4.14
- 4.15
- 4.16
- 4.17
- 4.18
- 8.0
- 9.0
- 10.0
- 8.4
- 8.6
- 8.8
- 9.4
- 9.6
- 10.0
- 8.0_aarch64
- 9.0_aarch64
- 9.4_aarch64
- 10.0_aarch64
- 9.4_aarch64
- 9.6_aarch64
- 10.0_aarch64
- 8.0_s390x
- 9.4_s390x
- 10.0_s390x
- 9.0_s390x
- 9.4_s390x
- 9.6_s390x
- 10.0_s390x
- 8.0_ppc64le
- 9.0_ppc64le
- 10.0_ppc64le
- 9.4_ppc64le
- 9.6_ppc64le
- 10.0_ppc64le
- 7.0
- 8.2
- 8.4
- 8.6
- 9.2
- 9.4
- 9.6
- 9.4_ppc64le
- 8.8
- 1.0
No data.
Red Hat Discovery 2
discovery/discovery-server-rhel9:2.0.1-1754478727
Fixed · RHSA-2025:13267
Red Hat Enterprise Linux 10
libxml2-0:2.12.5-7.el10_0
Fixed · RHSA-2025:10630
Red Hat Enterprise Linux 7 Extended Lifecycle Support
libxml2-0:2.9.1-6.el7_9.10
Fixed · RHSA-2025:12240
Red Hat Enterprise Linux 8
libxml2-0:2.9.7-21.el8_10.1
Fixed · RHSA-2025:10698
Red Hat Enterprise Linux 8
libxml2-0:2.9.7-21.el8_10.1
Fixed · RHSA-2025:10698
Red Hat Enterprise Linux 8.2 Advanced Update Support
libxml2-0:2.9.7-9.el8_2.3
Fixed · RHSA-2025:12237
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
libxml2-0:2.9.7-9.el8_4.6
Fixed · RHSA-2025:12241
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
libxml2-0:2.9.7-9.el8_4.6
Fixed · RHSA-2025:12241
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
libxml2-0:2.9.7-13.el8_6.10
Fixed · RHSA-2025:12098
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
libxml2-0:2.9.7-13.el8_6.10
Fixed · RHSA-2025:12098
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
libxml2-0:2.9.7-13.el8_6.10
Fixed · RHSA-2025:12098
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
libxml2-0:2.9.7-16.el8_8.9
Fixed · RHSA-2025:12239
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
libxml2-0:2.9.7-16.el8_8.9
Fixed · RHSA-2025:12239
Red Hat Enterprise Linux 9
libxml2-0:2.9.13-10.el9_6
Fixed · RHSA-2025:10699
Red Hat Enterprise Linux 9
libxml2-0:2.9.13-10.el9_6
Fixed · RHSA-2025:10699
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
libxml2-0:2.9.13-1.el9_0.5
Fixed · RHSA-2025:12099
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
libxml2-0:2.9.13-3.el9_2.7
Fixed · RHSA-2025:12199
Red Hat Enterprise Linux 9.4 Extended Update Support
libxml2-0:2.9.13-10.el9_4
Fixed · RHSA-2025:11580
Red Hat Hardened Images
libxml2-main-2.15.2-0.3.hum1
Fixed · RHSA-2026:7519
Red Hat Insights proxy 1.5
insights-proxy/insights-proxy-container-rhel9:1.5.5-1754504343
Fixed · RHSA-2025:13335
Red Hat OpenShift Container Platform 4.12
rhcos-412.86.202509030110-0
Fixed · RHSA-2025:15308
Red Hat OpenShift Container Platform 4.13
rhcos-413.92.202509030117-0
Fixed · RHSA-2025:15672
Red Hat OpenShift Container Platform 4.14
rhcos-414.92.202508041909-0
Fixed · RHSA-2025:13289
Red Hat OpenShift Container Platform 4.15
rhcos-415.92.202508192014-0
Fixed · RHSA-2025:14396
Red Hat OpenShift Container Platform 4.16
rhcos-416.94.202508050040-0
Fixed · RHSA-2025:13336
Red Hat OpenShift Container Platform 4.17
rhcos-417.94.202508141510-0
Fixed · RHSA-2025:14059
Red Hat OpenShift Container Platform 4.18
rhcos-418.94.202508060022-0
Fixed · RHSA-2025:13325
Red Hat OpenShift Container Platform 4.19
rhcos-4.19.9.6.202507230107-0
Fixed · RHSA-2025:11673
Red Hat Enterprise Linux 6
libxml2
Out of support scope
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Discovery 2 | discovery/discovery-server-rhel9:2.0.1-1754478727 | Fixed | RHSA-2025:13267 |
| Red Hat Enterprise Linux 10 | libxml2-0:2.12.5-7.el10_0 | Fixed | RHSA-2025:10630 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | libxml2-0:2.9.1-6.el7_9.10 | Fixed | RHSA-2025:12240 |
| Red Hat Enterprise Linux 8 | libxml2-0:2.9.7-21.el8_10.1 | Fixed | RHSA-2025:10698 |
| Red Hat Enterprise Linux 8 | libxml2-0:2.9.7-21.el8_10.1 | Fixed | RHSA-2025:10698 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | libxml2-0:2.9.7-9.el8_2.3 | Fixed | RHSA-2025:12237 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | libxml2-0:2.9.7-9.el8_4.6 | Fixed | RHSA-2025:12241 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | libxml2-0:2.9.7-9.el8_4.6 | Fixed | RHSA-2025:12241 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | libxml2-0:2.9.7-13.el8_6.10 | Fixed | RHSA-2025:12098 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | libxml2-0:2.9.7-13.el8_6.10 | Fixed | RHSA-2025:12098 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | libxml2-0:2.9.7-13.el8_6.10 | Fixed | RHSA-2025:12098 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | libxml2-0:2.9.7-16.el8_8.9 | Fixed | RHSA-2025:12239 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | libxml2-0:2.9.7-16.el8_8.9 | Fixed | RHSA-2025:12239 |
| Red Hat Enterprise Linux 9 | libxml2-0:2.9.13-10.el9_6 | Fixed | RHSA-2025:10699 |
| Red Hat Enterprise Linux 9 | libxml2-0:2.9.13-10.el9_6 | Fixed | RHSA-2025:10699 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | libxml2-0:2.9.13-1.el9_0.5 | Fixed | RHSA-2025:12099 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | libxml2-0:2.9.13-3.el9_2.7 | Fixed | RHSA-2025:12199 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | libxml2-0:2.9.13-10.el9_4 | Fixed | RHSA-2025:11580 |
| Red Hat Hardened Images | libxml2-main-2.15.2-0.3.hum1 | Fixed | RHSA-2026:7519 |
| Red Hat Insights proxy 1.5 | insights-proxy/insights-proxy-container-rhel9:1.5.5-1754504343 | Fixed | RHSA-2025:13335 |
| Red Hat OpenShift Container Platform 4.12 | rhcos-412.86.202509030110-0 | Fixed | RHSA-2025:15308 |
| Red Hat OpenShift Container Platform 4.13 | rhcos-413.92.202509030117-0 | Fixed | RHSA-2025:15672 |
| Red Hat OpenShift Container Platform 4.14 | rhcos-414.92.202508041909-0 | Fixed | RHSA-2025:13289 |
| Red Hat OpenShift Container Platform 4.15 | rhcos-415.92.202508192014-0 | Fixed | RHSA-2025:14396 |
| Red Hat OpenShift Container Platform 4.16 | rhcos-416.94.202508050040-0 | Fixed | RHSA-2025:13336 |
| Red Hat OpenShift Container Platform 4.17 | rhcos-417.94.202508141510-0 | Fixed | RHSA-2025:14059 |
| Red Hat OpenShift Container Platform 4.18 | rhcos-418.94.202508060022-0 | Fixed | RHSA-2025:13325 |
| Red Hat OpenShift Container Platform 4.19 | rhcos-4.19.9.6.202507230107-0 | Fixed | RHSA-2025:11673 |
| Red Hat Enterprise Linux 6 | libxml2 | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Users are strongly advised to apply vendor-supplied patches as soon as they become available to address the underlying integer overflow flaw in the affected code.
Red Hat statement
This vulnerability is rated Moderate due to the lack of confidentiality impact and limited integrity concerns, with the main risk being potential denial-of-service from a crash. Exploitation requires crafted XML input and specific application behavior using xmlBuildQName. While it’s a write overflow, modern mitigations make remote code execution unlikely.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Users are strongly advised to apply vendor-supplied patches as soon as they become available to address the underlying integer overflow flaw in the affected code.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Sep 3, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (4 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.37% (0.01367) | 70.84th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.07% (0.01067) | 60.26th | v5 (v2026.06.15) |
| Nov 18, 2025 | 1.31% (0.01313) | 78.09th | v4 (v2025.03.14) |
| Jun 13, 2025 | 0.04% (0.00040) | 11.54th | v4 (v2025.03.14) |
References (30)
- https://access.redhat.com/errata/RHSA-2025:10630 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:10698 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:10699 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:11580 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:11673 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:12098 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12099 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12199 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12237 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12239 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12240 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12241 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:13267 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:13289 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:13325 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:13335 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:13336 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14059 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14396 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:15308 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:15672 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19020 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:7519 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-6021 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2372406 issue-trackingx_refsource_REDHATIssue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/926 exploitissue-trackingIssue TrackingVendor Advisory
- https://lists.debian.org/debian-lts-announce/2025/07/msg00014.html
- https://nvd.nist.gov/vuln/detail/CVE-2025-6021
- https://www.cve.org/CVERecord?id=CVE-2025-6021
Change history (0)
No recorded changes yet.