Описание
ELSA-2025-12450: libxml2 security update (IMPORTANT)
[2.9.7.21.2]
- Fix CVE-2025-7425 (RHEL-102797)
[2.9.7-21.1]
- Fix CVE-2025-6021 (RHEL-96498)
- Fix CVE-2025-49794 (RHEL-96398)
- Fix CVE-2025-49796 (RHEL-96424)
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
libxml2
2.9.7-21.el8_10.2
libxml2-devel
2.9.7-21.el8_10.2
python3-libxml2
2.9.7-21.el8_10.2
Oracle Linux x86_64
libxml2
2.9.7-21.el8_10.2
libxml2-devel
2.9.7-21.el8_10.2
python3-libxml2
2.9.7-21.el8_10.2
Связанные CVE
Связанные уязвимости
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
A flaw was found in libxslt where the attribute type, atype, flags are ...