PT-2025-7245 · Libxml2+10 · Libxml2+10
Published
2025-02-13
·
Updated
2026-05-08
·
CVE-2025-27113
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
libxml2 versions 2.12.10 and earlier, 2.13.x versions prior to 2.13.6
Description
The issue is related to a NULL pointer dereference in
xmlPatMatch in pattern.c. This is a general information about the problem, and no specific details about affected devices or real-world incidents are provided.Recommendations
For libxml2 versions 2.12.10 and earlier, update to version 2.12.10 or later.
For libxml2 version 2.13.x prior to 2.13.6, update to version 2.13.6 or later.
As a temporary workaround, consider disabling the
xmlPatMatch function in pattern.c until a patch is available.Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Ibm Aix
Java Platform
Linuxmint
Apple Macos
Red Os
Suse
Ubuntu
Libxml2