vulnerability

Arch Linux: Denial of service (CVE-2025-49795)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Jun 16, 2025
Added
Jul 11, 2025
Modified
Nov 27, 2025

Description

A null pointer dereference vulnerability was discovered in the libxml2. The issue occurs in the xmlSchematronFormatReport function when processing incorrect XPath expressions in Schematron schema reports, leading to undefined behavior and potential crashes.

The xmlXPathCompiledEval() function can return NULL when evaluating invalid XPath expressions, but the code immediately dereferences the returned pointer without checking for NULL.

Solution

arch-linux-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.