← Back

CVE-2025-6170

nvd nist
Published: Jun 16, 2025Modified: Jul 23, 2026

JSON object

Loading...
2.5
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
Exploitability: 1.0 / Impact: 1.4
Source: NVD

Description

A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.

Affected (8)

3 products
Enterprise Linux
Jboss Core Services
Openshift Container Platform
1 product
Libxml2
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 10.0
Version 6.0
Version 7.0
Version 8.0
Version 9.0
All versions
Version 4.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (10)

Source: secalert@redhat.com
MitigationThird Party Advisory
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e

Timeline

No history available yet.