Release Info

Advisory: CLSA-2025:1757015069

OS: Ubuntu 16.04 ELS

Public date: 2025-09-04 19:44:31.939235

Project: libxml2

Version: 2.9.3+dfsg1-1ubuntu0.7+tuxcare.els11

Errata link: https://errata.tuxcare.com/els_os/ubuntu16.04els/CLSA-2025-1757015069.html

Changelog

* SECURITY UPDATE: stack-based buffer overflow via integer overflows in buffer size calculations in xmlBuildQName function - debian/patches/CVE-2025-6021.patch: Fix integer overflow in xmlBuildQName that affects memory safety - CVE-2025-6021

Update

Update command: apt-get update apt-get --only-upgrade install libxml2*

Packages list

libxml2_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els11_amd64.deb libxml2-dev_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els11_amd64.deb libxml2-doc_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els11_all.deb libxml2-utils_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els11_amd64.deb python-libxml2_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els11_amd64.deb

CVEs

CVE-2025-6021