CVE-2025-49794

Updated: 2025-08-20 03:16:27.884659

Description:

A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x HIGH 9.1

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU libxml2 2.9.13 9.1 HIGH Released CLSA-2025:1752747463 2025-07-18 02:05:53
Alpine Linux 3.18 ELS libxml2 2.11.8 9.1 HIGH Needs Triage 2026-02-11 11:55:56
CentOS 6 ELS libxml2 2.7.6 9.1 HIGH Released CLSA-2025:1753377886 2025-08-09 01:42:32
CentOS 7 ELS libxml2 2.9.1 9.1 HIGH Released CLSA-2025:1753303283 2025-08-05 02:11:41
CentOS 8.4 ELS libxml2 2.9.7-9 9.1 HIGH Released CLSA-2025:1752654760 2025-07-17 06:42:59
CentOS 8.5 ELS libxml2 2.9.7-9 9.1 HIGH Released CLSA-2025:1752655171 2025-07-17 06:42:57
CentOS Stream 8 ELS libxml2 2.9.7 9.1 HIGH Released CLSA-2025:1752654590 2025-07-17 06:43:00
CloudLinux 6 ELS libxml2 2.7.6 9.1 HIGH Released CLSA-2025:1753378254 2025-08-06 05:51:45
CloudLinux 7 ELS libxml2 2.9.1 9.1 HIGH Released CLSA-2025:1753303387 2025-08-06 03:12:27
Debian 10 ELS libxml2 2.9.4 9.1 HIGH Needs Triage 2026-02-11 11:56:05
Total: 17