Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-49795

Опубликовано: 11 июн. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.

Отчет

This vulnerability marked as Important rather than Moderate due to its triggerability through untrusted input and impact on availability in a widely-used XML processing library like libxml2, which is often embedded in system-level and server-side applications. Although it is "just" a NULL pointer dereference—typically classified as a DoS—the context significantly elevates its severity. libxml2 frequently operates in environments that parse external XML content, such as web services, security scanners, and document processors. A crafted XML exploiting malformed XPath in Schematron schemas can reliably crash the application without requiring special privileges or user interaction.

Меры по смягчению последствий

Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libxml2Out of support scope
Red Hat Enterprise Linux 7libxml2Not affected
Red Hat Enterprise Linux 8libxml2Not affected
Red Hat Enterprise Linux 9libxml2Not affected
Red Hat JBoss Core Serviceslibxml2Affected
Red Hat Enterprise Linux 10libxml2FixedRHSA-2025:1063008.07.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2372379libxml: Null pointer dereference leads to Denial of service (DoS)

EPSS

Процентиль: 17%
0.00054
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.

CVSS3: 7.5
nvd
около 2 месяцев назад

A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.

CVSS3: 7.5
debian
около 2 месяцев назад

A NULL pointer dereference vulnerability was found in libxml2 when pro ...

CVSS3: 7.5
github
около 2 месяцев назад

A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.

CVSS3: 7.5
fstec
2 месяца назад

Уязвимость функции xmlSchematronFormatReport() компонента Schematron Schema Report библиотеки libxml2, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 17%
0.00054
Низкий

7.5 High

CVSS3