Vulnerability Intelligence Report
Libxml: heap use after free (uaf) leads to denial of service (dos)
CVE-2025-49794
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.
No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
Exploitability:3.9
Impact Score:5.2
EPSS Probability:0.83%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-825 ↗Expired Pointer Dereference
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| 0 < 2.15.0 (affected) | ||
| Red Hat | Red Hat Enterprise Linux 10 | 0:2.12.5-7.el10_0 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:2.9.1-6.el7_9.10 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8 | 0:2.9.7-21.el8_10.1 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8 | 0:2.9.7-21.el8_10.1 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.2 Advanced Update Support | 0:2.9.7-9.el8_2.3 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:2.9.7-9.el8_4.6 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 0:2.9.7-9.el8_4.6 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:2.9.7-13.el8_6.10 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.6 Telecommunications Update Service | 0:2.9.7-13.el8_6.10 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | 0:2.9.7-13.el8_6.10 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:2.9.7-16.el8_8.9 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:2.9.7-16.el8_8.9 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9 | 0:2.9.13-10.el9_6 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9 | 0:2.9.13-10.el9_6 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | 0:2.9.13-1.el9_0.5 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:2.9.13-3.el9_2.7 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.4 Extended Update Support | 0:2.9.13-10.el9_4 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 412.86.202510291903-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 413.92.202510150118-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 414.92.202510211419-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 416.94.202609011112-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 417.94.202510112152-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 418.94.202510230424-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 4.19.9.6.202510140714-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 4.20.9.6.202509251656-0 < * (unaffected) |
| Red Hat | Red Hat Web Terminal 1.11 on RHEL 9 | 1.11-19 < * (unaffected) |
| Red Hat | Red Hat Web Terminal 1.11 on RHEL 9 | 1.11-8 < * (unaffected) |
| Red Hat | Red Hat Web Terminal 1.12 on RHEL 9 | 1.12-4 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-11 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-11 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-11 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-10 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-10 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-4 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-9 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-12 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-18 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-11 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-7 < * (unaffected) |
| Red Hat | cert-manager operator for Red Hat OpenShift 1.16 | v1.16.5-1760515757 < * (unaffected) |
| Red Hat | OpenShift File Integrity Operator - FIO 1 | v1.3 < * (unaffected) |
| Red Hat | Red Hat Hardened Images | 2.15.2-0.3.hum1 < * (unaffected) |
| Red Hat | Red Hat Insights proxy 1.5 | 1.5.5-1754504343 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 6 | all |
| Red Hat | Red Hat OpenShift Container Platform 4 | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.833%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2025-06-10T22:17:05 |
| Published | 2025-06-16T15:24:31 |
| Patch Date | 2025-06-10 |
| Last Updated | 2026-09-18T17:22:55 |
Community Chatter & Buzz