Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:02617-1

Опубликовано: 04 авг. 2025
Источник: suse-cvrf

Описание

Security update for libxml2

This update for libxml2 fixes the following issues:

  • CVE-2025-7425: Fixed heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr (bsc#1246296)

Список пакетов

Container bci/bci-sle15-kernel-module-devel:latest
libxml2-2-2.12.10-150700.4.6.1
Container bci/kiwi:latest
libxml2-2-2.12.10-150700.4.6.1
libxml2-devel-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Container bci/php-apache:latest
libxml2-2-2.12.10-150700.4.6.1
Container bci/php-fpm:latest
libxml2-2-2.12.10-150700.4.6.1
Container bci/php:latest
libxml2-2-2.12.10-150700.4.6.1
Container bci/spack:latest
libxml2-2-2.12.10-150700.4.6.1
Container private-registry/1.2/harbor-portal:latest
libxml2-2-2.12.10-150700.4.6.1
Container private-registry/harbor-portal:latest
libxml2-2-2.12.10-150700.4.6.1
Container suse/bind:9
libxml2-2-2.12.10-150700.4.6.1
Container suse/hpc/warewulf4-x86_64/sle-hpc-node:latest
libxml2-2-2.12.10-150700.4.6.1
Container suse/kiosk/firefox-esr:latest
libxml2-2-2.12.10-150700.4.6.1
Container suse/kiosk/pulseaudio:latest
libxml2-2-2.12.10-150700.4.6.1
Container suse/kiosk/xorg:latest
libxml2-2-2.12.10-150700.4.6.1
Container suse/mariadb:latest
libxml2-2-2.12.10-150700.4.6.1
Container suse/multi-linux-manager/5.1/x86_64/proxy-httpd:latest
libxml2-2-2.12.10-150700.4.6.1
Container suse/multi-linux-manager/5.1/x86_64/proxy-salt-broker:latest
libxml2-2-2.12.10-150700.4.6.1
Container suse/multi-linux-manager/5.1/x86_64/proxy-squid:latest
libxml2-2-2.12.10-150700.4.6.1
Container suse/multi-linux-manager/5.1/x86_64/server-migration-14-16:latest
libxml2-2-2.12.10-150700.4.6.1
Container suse/multi-linux-manager/5.1/x86_64/server-saline:latest
libxml2-2-2.12.10-150700.4.6.1
Container suse/multi-linux-manager/5.1/x86_64/server:latest
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Container suse/nginx:1.21
libxml2-2-2.12.10-150700.4.6.1
Container suse/pcp:latest
libxml2-2-2.12.10-150700.4.6.1
Container suse/postgres:16
libxml2-2-2.12.10-150700.4.6.1
Container suse/postgres:16.14
libxml2-2-2.12.10-150700.4.6.1
Container suse/postgres:17
libxml2-2-2.12.10-150700.4.6.1
Container suse/postgres:17.10
libxml2-2-2.12.10-150700.4.6.1
Container suse/postgres:latest
libxml2-2-2.12.10-150700.4.6.1
Container suse/rmt-server:latest
libxml2-2-2.12.10-150700.4.6.1
Container suse/samba-client:latest
libxml2-2-2.12.10-150700.4.6.1
Container suse/samba-server:latest
libxml2-2-2.12.10-150700.4.6.1
Container suse/samba-toolbox:latest
libxml2-2-2.12.10-150700.4.6.1
Container suse/sle15:latest
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-Azure-3P
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-Azure-Basic
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-Azure-Standard
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-BYOS-Azure
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-BYOS-EC2
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-BYOS-GCE
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-CHOST-BYOS-Aliyun
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-CHOST-BYOS-Azure
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-CHOST-BYOS-EC2
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-CHOST-BYOS-GCE
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-CHOST-BYOS-GDC
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-CHOST-BYOS-SAP-CCloud
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-EC2
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-EC2-ECS-HVM
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-GCE
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-GCE-3P
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-HPC-Azure
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-HPC-BYOS-Azure
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-HPC-BYOS-EC2
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-HPC-BYOS-GCE
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-Hardened-BYOS-Azure
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-Hardened-BYOS-EC2
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-Hardened-BYOS-GCE
libxml2-2-2.12.10-150700.4.6.1
Image SLES15-SP7-SAP-Azure
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-SAP-Azure-3P
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-SAP-Azure-LI-BYOS-Production
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-SAP-Azure-VLI-BYOS-Production
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-SAP-BYOS-Azure
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-SAP-BYOS-EC2
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-SAP-BYOS-GCE
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-SAP-EC2
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-SAP-GCE
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-SAP-GCE-3P
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-SAP-Hardened-Azure
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-SAP-Hardened-BYOS-Azure
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-SAP-Hardened-BYOS-EC2
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-SAP-Hardened-BYOS-GCE
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-SAP-Hardened-GCE
libxml2-2-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-SAPCAL-Azure
libxml2-2-2.12.10-150700.4.6.1
libxml2-devel-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-SAPCAL-EC2
libxml2-2-2.12.10-150700.4.6.1
libxml2-devel-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image SLES15-SP7-SAPCAL-GCE
libxml2-2-2.12.10-150700.4.6.1
libxml2-devel-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
Image proxy-httpd-image
libxml2-2-2.12.10-150700.4.6.1
Image proxy-salt-broker-image
libxml2-2-2.12.10-150700.4.6.1
Image proxy-squid-image
libxml2-2-2.12.10-150700.4.6.1
Image server-database-migration-image
libxml2-2-2.12.10-150700.4.6.1
Image server-image
libxml2-2-2.12.10-150700.4.6.1
Image server-image-sles15sp7
libxml2-2-2.12.10-150700.4.6.1
Image server-migration-14-16-image
libxml2-2-2.12.10-150700.4.6.1
Image server-saline-image
libxml2-2-2.12.10-150700.4.6.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
libxml2-2-2.12.10-150700.4.6.1
libxml2-2-32bit-2.12.10-150700.4.6.1
libxml2-devel-2.12.10-150700.4.6.1
libxml2-tools-2.12.10-150700.4.6.1
python3-libxml2-2.12.10-150700.4.6.1
SUSE Linux Enterprise Module for Python 3 15 SP7
python311-libxml2-2.12.10-150700.4.6.1

Описание

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:libxml2-2-2.12.10-150700.4.6.1
Container bci/kiwi:latest:libxml2-2-2.12.10-150700.4.6.1
Container bci/kiwi:latest:libxml2-devel-2.12.10-150700.4.6.1
Container bci/kiwi:latest:libxml2-tools-2.12.10-150700.4.6.1

Ссылки