CVE-2025-6021
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: secalert@redhat.com (Secondary)
Description
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
Affected (72)
Products: Xmlsoft: Libxml2 · Redhat: Enterprise Linux, Enterprise Linux Eus, Enterprise Linux For Arm 64, Enterprise Linux For Arm 64 Eus, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Ibm Z Systems Eus, Enterprise Linux For Power Little Endian, Enterprise Linux For Power Little Endian Eus, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions, Enterprise Linux Server Tus, In Vehicle Operating System, Jboss Core Services, Openshift Container Platform, Openshift Container Platform For Arm64, Openshift Container Platform For Ibm Z, Openshift Container Platform For Linuxone, Openshift Container Platform For Power
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 | |
| Version 10.0 | |
| Version 10.0_aarch64 | |
| Version 10.0_aarch64 | |
| Version 10.0_s390x | |
| Version 10.0_s390x | |
| Version 10.0_ppc64le | |
| Version 10.0_ppc64le | |
| Version 7.0 | |
| Version 8.2 | |
| Version 9.4_ppc64le | |
| Version 8.8 | |
| Version 1.0 | |
| All versions | |
| Version 4.12 | |
| Version 4.13 | |
| Version 4.13 | |
| Version 4.13 | |
| Version 4.13 |
Related CWEs
CWE-121
Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-190
Integer Overflow or Wraparound
The product performs a calculation that can
produce an integer overflow or wraparound when the logic
assumes that the resulting value will always be larger than
the original value. This occurs when an integer value is
incremented to a value that is too large to store in the
associated representation. When this occurs, the value may
become a very small or negative number.
CWE-787
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
References (29)
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
ExploitIssue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitIssue TrackingVendor Advisory
Timeline
No history available yet.