PT-2025-45506 · Libxml2+1 · Libxml2+1
Published
2025-11-07
·
Updated
2026-04-16
·
CVE-2025-12863
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libxml2 (affected versions not specified)
Description
A flaw exists in the
xmlSetTreeDoc() function of the libxml2 XML parsing library. This function manages document pointers during XML node movements between documents. Improper handling of namespace references can result in a namespace pointer remaining linked to a freed memory region after the original document is destroyed. Subsequent access to this namespace can trigger a use-after-free condition, potentially leading to application crashes.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Libxml2