CVE-2025-6170

low
Published 2025-06-16 ยท Modified 2026-06-02
CVSS v3
2.5
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
2.5

Description

A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.

Predictions

Exploit likelihood
27%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling Red Hat statement The Red Hat Product Security team has rated the severity of this vulnerability as Low, since it affects only the interactive shell mode of the xmllint tool and requires a user to manually run the tool and enter or receive specially crafted input. The exploitation requires local access and aโ€ฆ

Description

libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling

Red Hat statement

The Red Hat Product Security team has rated the severity of this vulnerability as Low, since it affects only the interactive shell mode of the xmllint tool and requires a user to manually run the tool and enter or receive specially crafted input. The exploitation requires local access and a highly specific usage scenario that is uncommon in typical environments. While it can cause a crash, the impact is limited to availability, and exploitation is unlikely in real-world deployments.

CVSS v3: 2.5 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Hardened Imageslibxml2-main-2.15.2-0.3.hum1RHSA-2026:75192026-04-10T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 10libxml2Fix deferred
Red Hat Enterprise Linux 6libxml2Out of support scope
Red Hat Enterprise Linux 7libxml2Out of support scope
Red Hat Enterprise Linux 8libxml2Fix deferred
Red Hat Enterprise Linux 9libxml2Fix deferred
Red Hat JBoss Core Serviceslibxml2Fix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Apply commands

bash fix
Apply RHSA-2026:7519 for Red Hat Hardened Images
yum update -y libxml2-main
# or:
dnf upgrade -y libxml2-main

OS impact

arch Arch Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
redhat Red Hat Affected 5 releases
VersionStatusFixed in
10.0 Affected โ€”
9.0 Affected โ€”
8.0 Affected โ€”
7.0 Affected โ€”
6.0 Affected โ€”
suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.12.7+dfsg+really2.9.14-2.1
sid Fixed 2.12.7+dfsg+really2.9.14-2.1
forky Fixed 2.12.7+dfsg+really2.9.14-2.1
bullseye Fixed 2.9.10+dfsg-6.7+deb11u8
bookworm Fixed 2.9.14+dfsg-1.3~deb12u3

Application impact

VendorProductVersionsFixed
redhat redhatjboss_core_services-
redhat redhatopenshift_container_platform4.0
xmlsoftlibxml2-

References

CWEs

CWE-121

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.