CVE-2025-49794

Updated: 2025-08-20 03:16:27.884659

Description:

A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x HIGH 9.1

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Oracle Linux 6 ELS libxml2 2.7.6 9.1 HIGH Released CLSA-2025:1753374522 2025-07-25 02:05:52
Oracle Linux 7 ELS libxml2 2.9.1 9.1 HIGH Released CLSA-2025:1753298447 2025-07-24 01:54:12
RHEL 7 ELS libxml2 2.9.1 9.1 HIGH Released CLSA-2025:1753298958 2025-07-24 01:54:13
TuxCare 9.6 ESU libxml2 2.9.13 9.1 HIGH Needs Triage 2026-02-11 11:56:10
Ubuntu 16.04 ELS libxml2 2.9.3 9.1 HIGH Released CLSA-2025:1753729667 2025-07-29 04:51:24
Ubuntu 18.04 ELS libxml2 2.9.4 9.1 HIGH Released CLSA-2025:1753374216 2025-07-25 02:05:51
Ubuntu 20.04 ELS libxml2 2.9.10 9.1 HIGH Released CLSA-2025:1753298604 2025-07-24 01:54:15
Total: 17