Red Hat Enterprise Linux 10 vulnerability

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.

Published 12 Jun 2025Updated 18 Sep 202630 sources
CVSS 7.5 ✓ VERIFIED REFERENCE

What happened

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.

Affected versions

Red Hat Enterprise Linux 10: before 2.14.4 (semver); before V5.0 (custom) Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

RepositoryAuthorFirst seenReference
gitlab.gnome.orgNVD reference2025-06-12Verified