CVE-2025-6021
Last modified
CVE-2025-6021 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xmlsoft | Libxml2 | < 2.14.4 |
| Redhat | Jboss Core Services | All versions |
| Redhat | Openshift Container Platform | 4.12 |
| Redhat | Openshift Container Platform | 4.13 |
| Redhat | Openshift Container Platform | 4.14 |
| Redhat | Openshift Container Platform | 4.15 |
| Redhat | Openshift Container Platform | 4.16 |
| Redhat | Openshift Container Platform | 4.17 |
| Redhat | Openshift Container Platform | 4.18 |
| Redhat | Openshift Container Platform For Arm64 | 4.13 |
| Redhat | Openshift Container Platform For Arm64 | 4.14 |
| Redhat | Openshift Container Platform For Arm64 | 4.15 |
| Redhat | Openshift Container Platform For Arm64 | 4.16 |
| Redhat | Openshift Container Platform For Arm64 | 4.17 |
| Redhat | Openshift Container Platform For Arm64 | 4.18 |
| Redhat | Openshift Container Platform For Ibm Z | 4.13 |
| Redhat | Openshift Container Platform For Ibm Z | 4.14 |
| Redhat | Openshift Container Platform For Ibm Z | 4.15 |
| Redhat | Openshift Container Platform For Ibm Z | 4.16 |
| Redhat | Openshift Container Platform For Ibm Z | 4.17 |
| Redhat | Openshift Container Platform For Ibm Z | 4.18 |
| Redhat | Openshift Container Platform For Linuxone | 4.13 |
| Redhat | Openshift Container Platform For Linuxone | 4.14 |
| Redhat | Openshift Container Platform For Linuxone | 4.15 |
| Redhat | Openshift Container Platform For Linuxone | 4.16 |
| Redhat | Openshift Container Platform For Linuxone | 4.17 |
| Redhat | Openshift Container Platform For Linuxone | 4.18 |
| Redhat | Openshift Container Platform For Power | 4.13 |
| Redhat | Openshift Container Platform For Power | 4.14 |
| Redhat | Openshift Container Platform For Power | 4.15 |
| Redhat | Openshift Container Platform For Power | 4.16 |
| Redhat | Openshift Container Platform For Power | 4.17 |
| Redhat | Openshift Container Platform For Power | 4.18 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux | 9.0 |
| Redhat | Enterprise Linux | 10.0 |
| Redhat | Enterprise Linux Eus | 8.4 |
| Redhat | Enterprise Linux Eus | 8.6 |
| Redhat | Enterprise Linux Eus | 8.8 |
| Redhat | Enterprise Linux Eus | 9.4 |
| Redhat | Enterprise Linux Eus | 9.6 |
| Redhat | Enterprise Linux Eus | 10.0 |
| Redhat | Enterprise Linux For Arm 64 | 8.0_aarch64 |
| Redhat | Enterprise Linux For Arm 64 | 9.0_aarch64 |
| Redhat | Enterprise Linux For Arm 64 | 9.4_aarch64 |
| Redhat | Enterprise Linux For Arm 64 | 10.0_aarch64 |
| Redhat | Enterprise Linux For Arm 64 Eus | 9.4_aarch64 |
| Redhat | Enterprise Linux For Arm 64 Eus | 9.6_aarch64 |
| Redhat | Enterprise Linux For Arm 64 Eus | 10.0_aarch64 |
| Redhat | Enterprise Linux For Ibm Z Systems | 8.0_s390x |
Showing 50 of 72 affected configurations. See NVD for the full list.
References
- https://access.redhat.com/errata/RHSA-2025:10630Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:10698Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:10699Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:11580Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12098Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12099Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12199Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12237Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12239Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12240Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:12241Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:13267Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:13289Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:13325Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:13335Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:13336Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14059Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14396Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:15308Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:15672Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2025-6021Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2372406Issue Tracking
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/926Exploit, Issue Tracking, Vendor Advisory
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/926Exploit, Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-6021?
How severe is CVE-2025-6021?
How do I fix CVE-2025-6021?
Are you affected by CVE-2025-6021?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
