Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-11349

Опубликовано: 28 апр. 2026
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2026-11349: libxml2 security update (MODERATE)

[2.9.7-21.4]

  • Fix CVE-2025-9714 (RHEL-119279)

[2.9.7.21.3]

  • Fix CVE-2025-32415 (RHEL-100177)

[2.9.7.21.2]

  • Fix CVE-2025-7425 (RHEL-102797)

[2.9.7-21.1]

  • Fix CVE-2025-6021 (RHEL-96498)
  • Fix CVE-2025-49794 (RHEL-96398)
  • Fix CVE-2025-49796 (RHEL-96424)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

libxml2

2.9.7-21.el8_10.4

libxml2-devel

2.9.7-21.el8_10.4

python3-libxml2

2.9.7-21.el8_10.4

Oracle Linux x86_64

libxml2

2.9.7-21.el8_10.4

libxml2-devel

2.9.7-21.el8_10.4

python3-libxml2

2.9.7-21.el8_10.4

Связанные CVE

Связанные уязвимости

CVSS3: 6.2
ubuntu
11 месяцев назад

Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled.

CVSS3: 6.2
redhat
11 месяцев назад

Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled.

CVSS3: 6.2
nvd
11 месяцев назад

Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled.

CVSS3: 6.2
debian
11 месяцев назад

Uncontrolled recursion inXPath evaluationin libxml2 up to and includin ...

rocky
3 месяца назад

Moderate: libxml2 security update