PT-2025-7245 · Libxml2+10 · Libxml2+10

Published

2025-02-13

·

Updated

2026-05-08

·

CVE-2025-27113

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libxml2 versions 2.12.10 and earlier, 2.13.x versions prior to 2.13.6
Description The issue is related to a NULL pointer dereference in xmlPatMatch in pattern.c. This is a general information about the problem, and no specific details about affected devices or real-world incidents are provided.
Recommendations For libxml2 versions 2.12.10 and earlier, update to version 2.12.10 or later. For libxml2 version 2.13.x prior to 2.13.6, update to version 2.13.6 or later. As a temporary workaround, consider disabling the xmlPatMatch function in pattern.c until a patch is available.

Exploit

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2025-3794
ALT-PU-2025-3838
ALT-PU-2025-6978
AZL-56964
AZL-57058
BDU:2025-03138
BIT-JAVA-2025-27113
BIT-JAVA-MIN-2025-27113
BIT-JRE-2025-27113
CVE-2025-27113
DLA-4064-1
DSA-5949-1
ECHO-349D-8C18-8761
MGASA-2025-0073
OESA-2025-1225
OPENSUSE-SU-2025:14830-1
OPENSUSE-SU-2025_0746-1
OPENSUSE-SU-2025_0748-1
OPENSUSE-SU-2025_0976-1
SUSE-SU-2025:0746-1
SUSE-SU-2025:0747-1
SUSE-SU-2025:0748-1
SUSE-SU-2025:0976-1
SUSE-SU-2025:20177-1
SUSE-SU-2025:20274-1
USN-7302-1

Affected Products

Alt Linux
Astra Linux
Debian
Ibm Aix
Java Platform
Linuxmint
Apple Macos
Red Os
Suse
Ubuntu
Libxml2