Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-22420

Опубликовано: 29 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2026-22420: libxml2 security update (MODERATE)

[2.9.1-6.0.13.6]

  • Backport fix for CVE-2025-9714 [Orabug: 39476695]

[2.9.1-6.0.11.6]

  • Fix CVE-2025-32415: Fix heap buffer overflow [Orabug: 38310750]

[2.9.1-6.0.9.6]

  • Fix CVE-2025-7425: heap-use-after-free in xmlFreeID [Orabug: 38290330]

[2.9.1-6.0.7.6]

  • Fix CVE-2025-6021, CVE-2025-32414, CVE-2025-49794, CVE-2025-49796
  • [Orabug: 38255814]

[2.9.1-6.0.5]

  • Fix CVE-2024-56171 [Orabug: 37694105]
  • Fix CVE-2025-24928 [Orabug: 37694105]

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

libxml2

2.9.1-6.0.13.el7_9.6

libxml2-devel

2.9.1-6.0.13.el7_9.6

libxml2-python

2.9.1-6.0.13.el7_9.6

libxml2-static

2.9.1-6.0.13.el7_9.6

Связанные CVE

Связанные уязвимости

CVSS3: 6.2
ubuntu
11 месяцев назад

Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled.

CVSS3: 6.2
redhat
11 месяцев назад

Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled.

CVSS3: 6.2
nvd
11 месяцев назад

Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled.

CVSS3: 6.2
debian
11 месяцев назад

Uncontrolled recursion inXPath evaluationin libxml2 up to and includin ...

rocky
3 месяца назад

Moderate: libxml2 security update