Vulnerability Intelligence Report
Libxml: type confusion leads to denial of service (dos)
CVE-2025-49796
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.
No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
Exploitability:3.9
Impact Score:5.2
EPSS Probability:1.56%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-125 ↗Out-of-bounds Read
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| 0 < 2.15.0 (affected) | ||
| Red Hat | Red Hat Enterprise Linux 10 | 0:2.12.5-7.el10_0 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:2.9.1-6.el7_9.10 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8 | 0:2.9.7-21.el8_10.1 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8 | 0:2.9.7-21.el8_10.1 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.2 Advanced Update Support | 0:2.9.7-9.el8_2.3 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:2.9.7-9.el8_4.6 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 0:2.9.7-9.el8_4.6 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:2.9.7-13.el8_6.10 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.6 Telecommunications Update Service | 0:2.9.7-13.el8_6.10 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | 0:2.9.7-13.el8_6.10 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:2.9.7-16.el8_8.9 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:2.9.7-16.el8_8.9 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9 | 0:2.9.13-10.el9_6 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9 | 0:2.9.13-10.el9_6 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | 0:2.9.13-1.el9_0.5 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:2.9.13-3.el9_2.7 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.4 Extended Update Support | 0:2.9.13-10.el9_4 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 412.86.202510291903-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 413.92.202510150118-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 414.92.202510211419-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 416.94.202609011112-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 417.94.202510112152-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 418.94.202510230424-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 4.19.9.6.202510140714-0 < * (unaffected) |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 4.20.9.6.202509251656-0 < * (unaffected) |
| Red Hat | Red Hat Web Terminal 1.11 on RHEL 9 | 1.11-19 < * (unaffected) |
| Red Hat | Red Hat Web Terminal 1.11 on RHEL 9 | 1.11-8 < * (unaffected) |
| Red Hat | Red Hat Web Terminal 1.12 on RHEL 9 | 1.12-4 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-11 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-11 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-11 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-10 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-10 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-4 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-9 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-12 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-18 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-11 < * (unaffected) |
| Red Hat | RHOSS-1.36-RHEL-8 | 1.36.0-7 < * (unaffected) |
| Red Hat | cert-manager operator for Red Hat OpenShift 1.16 | v1.16.5-1760515757 < * (unaffected) |
| Red Hat | OpenShift File Integrity Operator - FIO 1 | v1.3 < * (unaffected) |
| Red Hat | Red Hat Discovery 2 | 2.0.1-1754478727 < * (unaffected) |
| Red Hat | Red Hat Hardened Images | 2.15.2-0.3.hum1 < * (unaffected) |
| Red Hat | Red Hat Insights proxy 1.5 | 1.5.5-1754504343 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 6 | all |
| Red Hat | Red Hat OpenShift Container Platform 4 | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.558%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2025-06-10T22:17:05 |
| Published | 2025-06-16T15:14:28 |
| Patch Date | 2025-06-11 |
| Last Updated | 2026-09-18T17:23:36 |
Community Chatter & Buzz