Executive brief
A critical vulnerability has been identified in libxml2, a widely used software library for processing XML data. This flaw allows an attacker to provide a specially crafted XML file that can cause applications using the library to crash or behave unpredictably. This could lead to a total service outage (Denial of Service) for any system that processes untrusted XML data using this component.
Technical details
A use-after-free (UAF) vulnerability exists in libxml2's XPath processing logic. The issue is triggered when the library parses XML Schematron documents containing specific '<sch:name path=\"...\"/>' schema elements. An attacker can exploit this by providing a malicious XML document to be processed by libxml2, leading to an expired pointer dereference (CWE-825). This results in a heap use-after-free condition that can cause a denial of service (DoS) via application crash or other undefined behaviors. Patches have been released by major distributions including Red Hat and Debian.
Affected products
- GNOME libxml2 versions prior to 2.12.5-7 (RHEL 10) and 2.9.7-21 (RHEL 8)
Timeline
- 2025-06-16: disclosed: Initial CVE publication date
- 2025-07-08: patched: Red Hat released security updates for RHEL 10
- 2025-07-09: patched: Red Hat released security updates for RHEL 8
References
- https://access.redhat.com/errata/RHSA-2025:10630
- https://access.redhat.com/errata/RHSA-2025:10698
- https://access.redhat.com/errata/RHSA-2025:10699
- https://access.redhat.com/errata/RHSA-2025:11580
- https://access.redhat.com/errata/RHSA-2025:12098
- https://access.redhat.com/errata/RHSA-2025:12099
- https://access.redhat.com/errata/RHSA-2025:12199