A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libxml2-develUpgrade libxml2Upgrade python3-libxml2 | Jul 14, 2025 | Jun 16, 2025 |
| Alpine Linux | — | Upgrade libxml2 | Oct 9, 2025 | Jun 16, 2025 |
| Amazon Linux Ami 2 | — | Upgrade libxml2-staticUpgrade libxml2-pythonUpgrade libxml2-debuginfoUpgrade libxml2-develUpgrade libxml2 | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade libxml2-staticUpgrade libxml2-debuginfoUpgrade python3-libxml2Upgrade libxml2-debugsourceUpgrade libxml2-develUpgrade libxml2Upgrade python3-libxml2-debuginfo | Jul 30, 2025 | Jun 10, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 16, 2025 |
| Debian | — | Upgrade libxml2 | Jun 16, 2025 | Jun 16, 2025 |
| Freebsd | — | Upgrade libxml2Upgrade linux-rl9-libxml2Upgrade linux-c7-libxml2 | Jul 13, 2025 | Jul 12, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade python3-libxml2Upgrade libxml2 | Sep 15, 2025 | Sep 9, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade libxml2Upgrade python3-libxml2 | Oct 14, 2025 | Sep 9, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade libxml2Upgrade python3-libxml2 | Sep 15, 2025 | Sep 9, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade python3-libxml2Upgrade libxml2 | Oct 24, 2025 | Sep 9, 2025 |
| Ibm Aix | — | Apply the fix or workaround for libxml2_advisory9 | Sep 25, 2025 | Jul 17, 2025 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Oct 10, 2025 |
| Oracle_linux | — | Upgrade libxml2-pythonUpgrade python3-libxml2Upgrade libxml2-develUpgrade libxml2Upgrade libxml2-static | Jul 10, 2025 | Jun 10, 2025 |
| Redhat Openshift | — | Upgrade rhcos | Aug 10, 2026 | Jun 10, 2025 |
| Redhat_linux | — | Upgrade libxml2-debuginfoUpgrade libxml2Upgrade python3-libxml2Upgrade libxml2-debugsourceUpgrade libxml2-develUpgrade libxml2-pythonUpgrade libxml2-staticNo solution existsUpgrade python3-libxml2-debuginfo | Jul 9, 2025 | Jun 16, 2025 |
| Rocky_linux | — | Upgrade libxml2Upgrade libxml2-debugsourceUpgrade python3-libxml2-debuginfoUpgrade python3-libxml2Upgrade libxml2-debuginfoUpgrade libxml2-staticUpgrade libxml2-devel | Feb 5, 2026 | Oct 4, 2025 |
| Suse | — | Upgrade python311-libxml2Upgrade libxml2-develUpgrade libxml2-toolsUpgrade python3-libxml2-pythonUpgrade python313-libxml2Upgrade libxml2-2Upgrade libxml2-devel-32bitUpgrade libxml2-docUpgrade python3-libxml2Upgrade python-libxml2Upgrade libxml2-2-32bit | Dec 5, 2025 | Jul 10, 2025 |
| Ubuntu | — | Upgrade libxml2 (Ubuntu Pro)Upgrade python-libxml2 (Ubuntu Pro)Upgrade python3-libxml2Upgrade python3-libxml2 (Ubuntu Pro)Upgrade libxml2 | Aug 21, 2025 | Jun 16, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 21, 2025 | Jun 16, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub