Junglewise Threat Intelligence

CVE-2025-49795: GNOME libxml2 NULL pointer dereference in XPath processing

CVE-2025-49795 · Severity: high · CVSS 7.5 · Published 2025-06-16

Technologies: Red Hat Enterprise Linux. Vendors: Gnome, Red Hat.

Executive brief

A vulnerability has been identified in libxml2, a widely used software library for processing XML data. An attacker can exploit this flaw by providing a specially crafted XML file, which causes the library to crash. This results in a denial-of-service condition, potentially disrupting applications or web services that rely on this library to handle data.

Technical details

A NULL pointer dereference vulnerability (CWE-825) exists in libxml2 during the processing of XPath XML expressions. The flaw is triggered when the library handles specifically crafted XML input, leading to an invalid memory access and subsequent process crash. This is a remote, unauthenticated attack vector requiring no user interaction. The vulnerability affects various Red Hat distributions and JBoss Core Services, with patches available in libxml2 version 2.12.5-7.el10_0 for RHEL 10 and JBoss Core Services Apache HTTP Server 2.4.62 SP2.

Affected products

  • GNOME libxml2 versions prior to 2.12.5-7.el10_0 (RHEL 10)
  • Red Hat Enterprise Linux 10
  • Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP2

Timeline

  • 2025-06-16: disclosed: Initial disclosure by Red Hat
  • 2025-07-08: patched: Red Hat released security update RHSA-2025:10630 for RHEL 10
  • 2025-10-27: patched: Red Hat released security update RHSA-2025:19020 for JBoss Core Services

References