Junglewise Threat Intelligence

CVE-2025-6021: GNOME libxml2 stack buffer overflow in xmlBuildQName

CVE-2025-6021 · Severity: high · CVSS 7.5 · Published 2025-06-12

Technologies: Red Hat Enterprise Linux, Red Hat OpenShift Container Platform. Vendors: Red Hat, Gnome.

Executive brief

libxml2 is a widely used software library for parsing XML data in various applications and operating systems. A vulnerability was found that allows an attacker to crash applications or potentially corrupt system memory by providing a specially crafted XML file. This could lead to a denial of service, impacting the availability of services that rely on this library to process external data.

Technical details

A stack-based buffer overflow vulnerability exists in libxml2 within the xmlBuildQName function. The root cause is an integer overflow during the calculation of buffer sizes when processing XML Qualified Names (QNames). An unauthenticated remote attacker can exploit this by providing specially crafted XML input, leading to memory corruption or a denial of service (application crash). The vulnerability is addressed in libxml2 version 2.14.4, and patches have been released by major distributions including Red Hat and Debian.

Affected products

  • GNOME libxml2 up to (excluding) 2.14.4
  • Red Hat Enterprise Linux 7, 8, 9, 10
  • Red Hat OpenShift Container Platform 4.12, 4.13

Timeline

  • 2025-06-12: disclosed
  • 2025-07-08: patched: Red Hat released initial security updates (RHSA-2025:10630)

References