PT-2024-1711 · Libxml2+13 · Libxml2+13

Published

2024-02-04

·

Updated

2026-05-08

·

CVE-2024-25062

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libxml2 versions 2.11.7 and earlier libxml2 versions 2.12.x through 2.12.4
Description A use-after-free flaw was found in the xmlValidatePopElement() function of the libxml2 library when using the XML Reader interface with DTD validation and XInclude expansion enabled. This issue can be exploited by a remote attacker to cause a denial of service by processing crafted XML documents, potentially leading to a crash. The estimated number of potentially affected devices is not specified.
Recommendations For libxml2 versions 2.11.7 and earlier, update to version 2.11.7 or later. For libxml2 versions 2.12.x through 2.12.4, update to version 2.12.5 or later. As a temporary workaround, consider disabling the xmlValidatePopElement() function when using the XML Reader interface with DTD validation and XInclude expansion enabled until a patch is available. Restrict access to crafted XML documents to minimize the risk of exploitation.

Exploit

Fix

DoS

Use After Free

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2024:2679
ALSA-2024:3626
ALT-PU-2024-2019
ALT-PU-2024-3790
ALT-PU-2025-3794
ALT-PU-2025-3838
AZL-34290
AZL-34961
BDU:2024-01415
BIT-JAVA-2024-25062
BIT-JAVA-MIN-2024-25062
BIT-JRE-2024-25062
CESA-2024_3626
CVE-2024-25062
DLA-4064-1
DSA-5949-1
ECHO-3385-DEC3-86A0
GHSA-XC9X-JJ77-9P9J
INFSA-2024_2679
INFSA-2024_3626
MGASA-2024-0172
OESA-2024-1183
OPENSUSE-SU-2024:13676-1
OPENSUSE-SU-2024_0461-2
OPENSUSE-SU-2024_0613-1
OPENSUSE-SU-2024_0613-2
RHSA-2024:2679
RHSA-2024:3299
RHSA-2024:3303
RHSA-2024:3625
RHSA-2024:3626
RHSA-2024_2679
RHSA-2024_3626
RLSA-2024:2679
RLSA-2024:3626
ROSA-SA-2025-2624
SUSE-SU-2024:0461-1
SUSE-SU-2024:0461-2
SUSE-SU-2024:0555-1
SUSE-SU-2024:0556-1
SUSE-SU-2024:0613-1
SUSE-SU-2024:0613-2
SUSE-SU-2024_0461-2
SUSE-SU-2024_0555-1
SUSE-SU-2024_0556-1
SUSE-SU-2024_0613-2
USN-6658-1
USN-6658-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Ibm Aix
Java Platform
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Libxml2