Release Info

Advisory: CLSA-2025:1753303387

OS: CloudLinux 7 ELS

Public date: 2025-07-23 20:42:57

Project: libxml2

Version: 2.9.1-6.0.3.el7_9.6.tuxcare.els5

Errata link: https://errata.cloudlinux.com/cloudlinux7els/CLSA-2025-1753303387.html

Changelog

- CVE-2025-49794: fix memory safety issues in xmlSchematronReportOutput when parsing XPath elements - CVE-2025-49796: fix memory corruption issue triggered by processing sch:name elements in input XML file

Update

Update command: yum update libxml2*

Packages list

libxml2-2.9.1-6.0.3.el7_9.6.tuxcare.els5.i686.rpm libxml2-2.9.1-6.0.3.el7_9.6.tuxcare.els5.x86_64.rpm libxml2-devel-2.9.1-6.0.3.el7_9.6.tuxcare.els5.i686.rpm libxml2-devel-2.9.1-6.0.3.el7_9.6.tuxcare.els5.x86_64.rpm libxml2-python-2.9.1-6.0.3.el7_9.6.tuxcare.els5.x86_64.rpm libxml2-static-2.9.1-6.0.3.el7_9.6.tuxcare.els5.i686.rpm libxml2-static-2.9.1-6.0.3.el7_9.6.tuxcare.els5.x86_64.rpm

CVEs

CVE-2025-49794
CVE-2025-49796