rpm package
almalinux/libxml2-devel
pkg:rpm/almalinux/libxml2-devel
Vulnerabilities (34)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-74860 | Hig | 8.5 | < 2.9.13-14.el9_8.5 | 2.9.13-14.el9_8.5 | Sep 8, 2026 | A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX at | |
| CVE-2026-86144 | Med | 5.6 | < 2.9.13-14.el9_8.5 | 2.9.13-14.el9_8.5 | Sep 5, 2026 | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity | |
| CVE-2026-86143 | Med | 6.9 | < 2.9.13-14.el9_8.5 | 2.9.13-14.el9_8.5 | Sep 5, 2026 | In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length | |
| CVE-2026-86142 | Med | 6.9 | < 2.9.13-14.el9_8.5 | 2.9.13-14.el9_8.5 | Sep 5, 2026 | In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. | |
| CVE-2026-86140 | Hig | 8.0 | < 2.9.13-14.el9_8.5 | 2.9.13-14.el9_8.5 | Sep 5, 2026 | In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow. | |
| CVE-2026-86138 | Med | 6.9 | < 2.9.13-14.el9_8.5 | 2.9.13-14.el9_8.5 | Sep 5, 2026 | In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. | |
| CVE-2026-11979 | Hig | 7.8 | < 2.12.5-10.el10_2.3 | 2.12.5-10.el10_2.3 | Jun 29, 2026 | libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker | |
| CVE-2026-6653 | Cri | 9.8 | < 2.9.13-14.el9_8.4 | 2.9.13-14.el9_8.4 | Jun 22, 2026 | Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling. | |
| CVE-2025-9714 | Med | 6.2 | < 2.9.13-14.el9_7 | 2.9.13-14.el9_7 | Sep 10, 2025 | Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion | |
| CVE-2025-7425 | Hig | 7.8 | < 2.9.13-11.el9_6 | 2.9.13-11.el9_6 | Jul 10, 2025 | A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, | |
| CVE-2025-6170 | Low | 2.5 | < 2.9.7-21.el8_10.6 | 2.9.7-21.el8_10.6 | Jun 16, 2025 | A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code | |
| CVE-2025-49796 | Cri | 9.1 | < 2.12.5-7.el10_0 | 2.12.5-7.el10_0 | Jun 16, 2025 | A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other poss | |
| CVE-2025-49795 | Hig | 7.5 | < 2.12.5-7.el10_0 | 2.12.5-7.el10_0 | Jun 16, 2025 | A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service. | |
| CVE-2025-49794 | Cri | 9.1 | < 2.12.5-7.el10_0 | 2.12.5-7.el10_0 | Jun 16, 2025 | A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as inpu | |
| CVE-2025-6021 | Hig | 7.5 | < 2.12.5-7.el10_0 | 2.12.5-7.el10_0 | Jun 12, 2025 | A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input. | |
| CVE-2025-32415 | Low | 2.9 | < 2.9.7-21.el8_10.3 | 2.9.7-21.el8_10.3 | Apr 17, 2025 | In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be use | |
| CVE-2025-32414 | Med | 5.6 | < 2.9.13-12.el9_6 | 2.9.13-12.el9_6 | Apr 8, 2025 | In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xmlPythonFileRead and xmlPythonFileReadRaw because of a difference between bytes and characters. | |
| CVE-2025-24928 | Hig | 7.8 | < 2.9.13-6.el9_5.2 | 2.9.13-6.el9_5.2 | Feb 18, 2025 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047. | |
| CVE-2024-56171 | Hig | 7.8 | < 2.9.13-6.el9_5.2 | 2.9.13-6.el9_5.2 | Feb 18, 2025 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML | |
| CVE-2022-49043 | Hig | 8.1 | < 2.9.13-6.el9_5.1 | 2.9.13-6.el9_5.1 | Jan 26, 2025 | xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free. |
- affected < 2.9.13-14.el9_8.5fixed 2.9.13-14.el9_8.5
A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX at
- affected < 2.9.13-14.el9_8.5fixed 2.9.13-14.el9_8.5
In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity
- affected < 2.9.13-14.el9_8.5fixed 2.9.13-14.el9_8.5
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length
- affected < 2.9.13-14.el9_8.5fixed 2.9.13-14.el9_8.5
In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
- affected < 2.9.13-14.el9_8.5fixed 2.9.13-14.el9_8.5
In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
- affected < 2.9.13-14.el9_8.5fixed 2.9.13-14.el9_8.5
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
- affected < 2.12.5-10.el10_2.3fixed 2.12.5-10.el10_2.3
libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker
- affected < 2.9.13-14.el9_8.4fixed 2.9.13-14.el9_8.4
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
- affected < 2.9.13-14.el9_7fixed 2.9.13-14.el9_7
Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion
- affected < 2.9.13-11.el9_6fixed 2.9.13-11.el9_6
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result,
- affected < 2.9.7-21.el8_10.6fixed 2.9.7-21.el8_10.6
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code
- affected < 2.12.5-7.el10_0fixed 2.12.5-7.el10_0
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other poss
- affected < 2.12.5-7.el10_0fixed 2.12.5-7.el10_0
A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.
- affected < 2.12.5-7.el10_0fixed 2.12.5-7.el10_0
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as inpu
- affected < 2.12.5-7.el10_0fixed 2.12.5-7.el10_0
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
- affected < 2.9.7-21.el8_10.3fixed 2.9.7-21.el8_10.3
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be use
- affected < 2.9.13-12.el9_6fixed 2.9.13-12.el9_6
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xmlPythonFileRead and xmlPythonFileReadRaw because of a difference between bytes and characters.
- affected < 2.9.13-6.el9_5.2fixed 2.9.13-6.el9_5.2
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.
- affected < 2.9.13-6.el9_5.2fixed 2.9.13-6.el9_5.2
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML
- affected < 2.9.13-6.el9_5.1fixed 2.9.13-6.el9_5.1
xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.
Page 1 of 2