A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a de…
High CVSS 7.5
Summary
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
Sources
- NVD DATABASE
Original Links
- https://access.redhat.com/errata/RHSA-2025:10630 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:10698 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:10699 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:11580 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:11673
- https://access.redhat.com/errata/RHSA-2025:12098 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12099 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12199 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12237 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12239 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12240 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12241 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:13267 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:13289 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:13325 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:13335 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:13336 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14059 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14396 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:15308 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:15672 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19020
- https://access.redhat.com/errata/RHSA-2026:7519
- https://access.redhat.com/security/cve/CVE-2025-6021 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2372406 Issue Tracking
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/926 Exploit
- https://lists.debian.org/debian-lts-announce/2025/07/msg00014.html
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/926 Exploit
Timeline
- nvd_ingest NVD