A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libxml2Upgrade python3-libxml2Upgrade libxml2-devel | Jul 14, 2025 | Jun 16, 2025 |
| Alpine Linux | — | Upgrade libxml2 | Oct 9, 2025 | Jun 16, 2025 |
| Amazon Linux Ami 2 | — | Upgrade libxml2-pythonUpgrade libxml2-staticUpgrade libxml2Upgrade libxml2-debuginfoUpgrade libxml2-devel | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade libxml2-debugsourceUpgrade libxml2-develUpgrade python3-libxml2Upgrade python3-libxml2-debuginfoUpgrade libxml2Upgrade libxml2-debuginfoUpgrade libxml2-static | Jul 30, 2025 | Jun 10, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 16, 2025 |
| Debian | — | Upgrade libxml2 | Jun 16, 2025 | Jun 16, 2025 |
| Freebsd | — | Upgrade linux-rl9-libxml2Upgrade linux-c7-libxml2Upgrade libxml2 | Jul 13, 2025 | Jul 12, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade libxml2Upgrade python3-libxml2 | Sep 15, 2025 | Sep 9, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade python3-libxml2Upgrade libxml2 | Oct 14, 2025 | Sep 9, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade libxml2Upgrade python3-libxml2 | Sep 15, 2025 | Sep 9, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade python3-libxml2Upgrade libxml2 | Oct 24, 2025 | Sep 9, 2025 |
| Ibm Aix | — | Apply the fix or workaround for libxml2_advisory9 | Sep 25, 2025 | Jul 17, 2025 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Oct 10, 2025 |
| Oracle_linux | — | Upgrade libxml2Upgrade python3-libxml2Upgrade libxml2-staticUpgrade libxml2-develUpgrade libxml2-python | Jul 10, 2025 | Jun 10, 2025 |
| Redhat Openshift | — | Upgrade rhcos | Aug 10, 2026 | Jun 10, 2025 |
| Redhat_linux | — | Upgrade python3-libxml2-debuginfoNo solution existsUpgrade libxml2-debugsourceUpgrade libxml2Upgrade libxml2-staticUpgrade libxml2-develUpgrade python3-libxml2Upgrade libxml2-debuginfoUpgrade libxml2-python | Jul 9, 2025 | Jun 16, 2025 |
| Rocky_linux | — | Upgrade libxml2-develUpgrade libxml2-staticUpgrade libxml2-debuginfoUpgrade libxml2-debugsourceUpgrade python3-libxml2Upgrade libxml2Upgrade python3-libxml2-debuginfo | Feb 5, 2026 | Oct 4, 2025 |
| Suse | — | Upgrade python-libxml2Upgrade libxml2-2-32bitUpgrade python3-libxml2Upgrade libxml2-docUpgrade python3-libxml2-pythonUpgrade libxml2-devel-32bitUpgrade python313-libxml2Upgrade python311-libxml2Upgrade libxml2-2Upgrade libxml2-toolsUpgrade libxml2-devel | Dec 5, 2025 | Jul 10, 2025 |
| Ubuntu | — | Upgrade python-libxml2 (Ubuntu Pro)Upgrade libxml2 (Ubuntu Pro)Upgrade libxml2Upgrade python3-libxml2 (Ubuntu Pro)Upgrade python3-libxml2 | Aug 21, 2025 | Jun 16, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 21, 2025 | Jun 16, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub