Executive brief
A vulnerability has been identified in libxml2, a widely used software library for processing XML data. An attacker could use a specially crafted XML file to cause the library to crash or behave unpredictably. This could lead to a service outage or the corruption of sensitive data in memory, potentially impacting any application that relies on this library to handle external data.
Technical details
A type confusion vulnerability exists in libxml2 when processing specific 'sch:name' elements within an input XML file. This flaw allows a remote, unauthenticated attacker to provide a malicious XML file that triggers memory corruption or an out-of-bounds read (CWE-125). Successful exploitation can lead to a denial of service (application crash) or other undefined behavior due to the corruption of sensitive data in memory. The issue has been addressed in various vendor updates, including Red Hat Enterprise Linux 8 and 10.
Affected products
- GNOME libxml2 versions prior to 2.12.5-7 (RHEL 10) and 2.9.7-21 (RHEL 8)
Timeline
- 2025-06-16: disclosed
- 2025-07-08: patched: Red Hat released security updates for RHEL 10
- 2025-07-09: patched: Red Hat released security updates for RHEL 8
References
- https://access.redhat.com/errata/RHSA-2025:10630
- https://access.redhat.com/errata/RHSA-2025:10698
- https://access.redhat.com/errata/RHSA-2025:10699
- https://access.redhat.com/errata/RHSA-2025:11580
- https://access.redhat.com/errata/RHSA-2025:12098
- https://access.redhat.com/errata/RHSA-2025:12099
- https://access.redhat.com/errata/RHSA-2025:12199