PT-2025-25521 · Libxml2+3 · Libxml2+3

Nikita Sveshnikov

·

Published

2025-01-01

·

Updated

2025-11-09

·

CVE-2025-49795

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libxml2 (affected versions not specified)
Description A NULL pointer dereference issue was discovered in libxml2 when processing XPath XML expressions. This allows an attacker to create malicious XML input, resulting in a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2025:10630
AZL-64098
AZL-64121
BDU:2025-08977
CVE-2025-49795
ECHO-44C5-A0A5-783A
GHSA-353F-X4GH-CQQ8
MGASA-2025-0269
OESA-2025-1768
OESA-2025-1769
OESA-2025-1770
OPENSUSE-SU-2025:15321-1
RHSA-2025:10630
RHSA-2026:7519
SUSE-SU-2025:02260-1
SUSE-SU-2025:02314-1
SUSE-SU-2025:20564-1
SUSE-SU-2025:20607-1
SUSE-SU-2025_02260-1
SUSE-SU-2025_02314-1

Affected Products

Debian
Ibm Aix
Suse
Libxml2