Release Info

Advisory: CLSA-2025:1746791922

OS: CentOS 8.4 ELS

Public date: 2025-05-09 11:58:44

Project: libxml2

Version: 2.9.7-9.el8_4.2.tuxcare.els10

Errata link: https://errata.cloudlinux.com/centos8.4-els/CLSA-2025-1746791922.html

Changelog

- CVE-2025-32415: fix heap-based buffer under-read in xmlSchemaIDCFillNodeTables function - CVE-2025-32414: fix out-of-bounds memory access in Python API by correcting return value in xmlPythonFileRead and xmlPythonFileReadRaw.

Update

Update command: dnf update libxml2*

Packages list

libxml2-2.9.7-9.el8_4.2.tuxcare.els10.i686.rpm libxml2-2.9.7-9.el8_4.2.tuxcare.els10.x86_64.rpm libxml2-devel-2.9.7-9.el8_4.2.tuxcare.els10.i686.rpm libxml2-devel-2.9.7-9.el8_4.2.tuxcare.els10.x86_64.rpm libxml2-static-2.9.7-9.el8_4.2.tuxcare.els10.x86_64.rpm python3-libxml2-2.9.7-9.el8_4.2.tuxcare.els10.x86_64.rpm

CVEs

CVE-2025-32415
CVE-2025-32414