CVE-2025-6021 PUBLISHED

Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2

Assigner: redhat
Reserved: 12.06.2025 Published: 12.06.2025 Updated: 30.06.2026

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Package Collection https://gitlab.gnome.org/GNOME/libxml2/
Package Name libxml2
Versions Default: unaffected
  • affected from 0 to 2.14.4 (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 10
Versions Default: affected
  • unaffected from 0:2.12.5-7.el10_0 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 7 Extended Lifecycle Support
Versions Default: affected
  • unaffected from 0:2.9.1-6.el7_9.10 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 8
Versions Default: affected
  • unaffected from 0:2.9.7-21.el8_10.1 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 8
Versions Default: affected
  • unaffected from 0:2.9.7-21.el8_10.1 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 8.2 Advanced Update Support
Versions Default: affected
  • unaffected from 0:2.9.7-9.el8_2.3 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Versions Default: affected
  • unaffected from 0:2.9.7-9.el8_4.6 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Versions Default: affected
  • unaffected from 0:2.9.7-9.el8_4.6 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Versions Default: affected
  • unaffected from 0:2.9.7-13.el8_6.10 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 8.6 Telecommunications Update Service
Versions Default: affected
  • unaffected from 0:2.9.7-13.el8_6.10 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
Versions Default: affected
  • unaffected from 0:2.9.7-13.el8_6.10 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Versions Default: affected
  • unaffected from 0:2.9.7-16.el8_8.9 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Versions Default: affected
  • unaffected from 0:2.9.7-16.el8_8.9 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 9
Versions Default: affected
  • unaffected from 0:2.9.13-10.el9_6 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 9
Versions Default: affected
  • unaffected from 0:2.9.13-10.el9_6 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
Versions Default: affected
  • unaffected from 0:2.9.13-1.el9_0.5 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Versions Default: affected
  • unaffected from 0:2.9.13-3.el9_2.7 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 9.4 Extended Update Support
Versions Default: affected
  • unaffected from 0:2.9.13-10.el9_4 to * (excl.)
Vendor Red Hat
Product Red Hat JBoss Core Services 2.4.62.SP2
Versions Default: unaffected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4.12
Versions Default: affected
  • unaffected from 412.86.202509030110-0 to * (excl.)
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4.13
Versions Default: affected
  • unaffected from 413.92.202509030117-0 to * (excl.)
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4.14
Versions Default: affected
  • unaffected from 414.92.202508041909-0 to * (excl.)
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4.15
Versions Default: affected
  • unaffected from 415.92.202508192014-0 to * (excl.)
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4.16
Versions Default: affected
  • unaffected from 416.94.202508050040-0 to * (excl.)
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4.17
Versions Default: affected
  • unaffected from 417.94.202508141510-0 to * (excl.)
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4.18
Versions Default: affected
  • unaffected from 418.94.202508060022-0 to * (excl.)
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4.19
Versions Default: affected
  • unaffected from 4.19.9.6.202507230107-0 to * (excl.)
Vendor Red Hat
Product Red Hat Discovery 2
Versions Default: affected
  • unaffected from 2.0.1-1754478727 to * (excl.)
Vendor Red Hat
Product Red Hat Hardened Images
Versions Default: affected
  • unaffected from 2.15.2-0.3.hum1 to * (excl.)
Vendor Red Hat
Product Red Hat Insights proxy 1.5
Versions Default: affected
  • unaffected from 1.5.5-1754504343 to * (excl.)
Vendor Red Hat
Product Red Hat Enterprise Linux 6
Versions Default: unknown

Workarounds

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Users are strongly advised to apply vendor-supplied patches as soon as they become available to address the underlying integer overflow flaw in the affected code.

Credits

  • Red Hat would like to thank Ahmed Lekssays for reporting this issue.

References

Problem Types

  • Out-of-bounds Write CWE