A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, …
Low CVSS 2.5
Summary
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
Sources
- NVD DATABASE
Original Links
- https://access.redhat.com/errata/RHSA-2026:36734
- https://access.redhat.com/errata/RHSA-2026:39304
- https://access.redhat.com/errata/RHSA-2026:7519
- https://access.redhat.com/security/cve/CVE-2025-6170 Mitigation
- https://bugzilla.redhat.com/show_bug.cgi?id=2372952 Issue Tracking
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/941
- https://lists.debian.org/debian-lts-announce/2025/07/msg00014.html
- https://cert-portal.siemens.com/productcert/html/ssa-253495.html
- https://access.redhat.com/errata/RHSA-2026:39317
Timeline
- nvd_ingest NVD