Vulnerabilities in the libxml2 library potentially leading to code execution

In the Libxml2 library, developed by the GNOME project and used for parsing XML content, five vulnerabilities have been identified, two of which could potentially lead to code execution when processing specially crafted external data. The Libxml2 library is widely used in open source projects and, for instance, is a dependency in over 800 packages in Ubuntu.

The first vulnerability (CVE-2025-6170) is caused by a buffer overflow in the interactive shell implementation xmllint, used for parsing XML files. The overflow occurs when processing very long command arguments due to a lack of proper input size checking before data is copied by the strcpy() function. To exploit the vulnerability, an attacker must have the ability to influence the commands passed to the xmllint utility. A patch to fix the vulnerability is not yet available.

The second vulnerability (CVE-2025-6021) exists in the implementation of the xmlBuildQName() function and leads to data being written beyond the buffer due to integer overflow when calculating the buffer size based on the prefix and local name. To exploit the vulnerability, an attacker must achieve substitution of their data in the arguments prefix and ncname passed to the xmlBuildQName() function. A patch has been prepared to fix the vulnerability. The fix is included in the release of libxml2 2.14.4. You can check the status of the new package version or the preparation of the fix in the distributions on the following pages (if the page is unavailable, it means the distribution maintainers have not yet begun addressing the issue): Debian, Ubuntu, Fedora, SUSE/openSUSE, RHEL, Gentoo, and Arch (1, 2).

The other three issues lead to crashes due to accessing freed memory in the xmlSchematronGetNode function (CVE-2025-49794), dereferencing a null pointer in the xmlXPathCompiledEval function (CVE-2025-49795), and improper type handling (Type Confusion) in the xmlSchematronFormatReport function (CVE-2025-49796). To address these vulnerabilities, the possibility of removing Schematron markup language support from libxml2 is being considered.

Additionally, three unresolved vulnerabilities have been noted in the libxslt library, which remains without support. Information on these issues has not yet been disclosed and is scheduled for publication on July 9, July 13, and August 6. Unresolved and not publicly disclosed vulnerabilities are also noted in related GNOME projects such as gvfs, libgxps, gdm, glib, GIMP, and libsoup.

Supplement: The maintainer of libxml2 has announced that vulnerabilities will now be treated as regular bugs, prioritizing them less and fixing them as time permits, while promptly disclosing the nature of the vulnerability without imposing an embargo or providing time for remediation in third-party products.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster