Release Info

Advisory: CLSA-2025:1753298447

OS: Oracle Linux 7 ELS

Public date: 2025-07-23 19:20:37

Project: libxml2

Version: 2.9.1-6.0.3.el7_9.6.tuxcare.els5

Errata link: https://errata.tuxcare.com/els_os/oraclelinux7els/CLSA-2025-1753298447.html

Changelog

- CVE-2025-49794: fix memory safety issues in xmlSchematronReportOutput when parsing XPath elements - CVE-2025-49796: fix memory corruption issue triggered by processing sch:name elements in input XML file

Update

Update command: yum update libxml2*

Packages list

libxml2-2.9.1-6.0.3.el7_9.6.tuxcare.els5.i686.rpm libxml2-2.9.1-6.0.3.el7_9.6.tuxcare.els5.x86_64.rpm libxml2-devel-2.9.1-6.0.3.el7_9.6.tuxcare.els5.i686.rpm libxml2-devel-2.9.1-6.0.3.el7_9.6.tuxcare.els5.x86_64.rpm libxml2-python-2.9.1-6.0.3.el7_9.6.tuxcare.els5.x86_64.rpm libxml2-static-2.9.1-6.0.3.el7_9.6.tuxcare.els5.i686.rpm libxml2-static-2.9.1-6.0.3.el7_9.6.tuxcare.els5.x86_64.rpm

CVEs

CVE-2025-49794
CVE-2025-49796