Junglewise Threat Intelligence

CVE-2025-49794: GNOME libxml2 use-after-free in XPath parsing

CVE-2025-49794 · Severity: critical · CVSS 9.1 · Published 2025-06-16

Vendors: Gnome.

Executive brief

A critical vulnerability has been identified in libxml2, a widely used software library for processing XML data. This flaw allows an attacker to provide a specially crafted XML file that can cause applications using the library to crash or behave unpredictably. This could lead to a total service outage (Denial of Service) for any system that processes untrusted XML data using this component.

Technical details

A use-after-free (UAF) vulnerability exists in libxml2's XPath processing logic. The issue is triggered when the library parses XML Schematron documents containing specific '<sch:name path=\"...\"/>' schema elements. An attacker can exploit this by providing a malicious XML document to be processed by libxml2, leading to an expired pointer dereference (CWE-825). This results in a heap use-after-free condition that can cause a denial of service (DoS) via application crash or other undefined behaviors. Patches have been released by major distributions including Red Hat and Debian.

Affected products

  • GNOME libxml2 versions prior to 2.12.5-7 (RHEL 10) and 2.9.7-21 (RHEL 8)

Timeline

  • 2025-06-16: disclosed: Initial CVE publication date
  • 2025-07-08: patched: Red Hat released security updates for RHEL 10
  • 2025-07-09: patched: Red Hat released security updates for RHEL 8

References