Use-after-free in Libxml2 - CVE-2025-49794

 

Use-after-free in Libxml2 - CVE-2025-49794

Published: June 17, 2025 / Updated: July 11, 2025


Vulnerability identifier: #VU111221
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-49794
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error within the xmlSchematronGetNode() function when processing XPath expressions in Schematron schema elements schematron.c. A remote attacker can pass specially crafted XML input to the application and perform a denial of service (DoS) attack.


Affected software

Libxml2
IBM Observability with Instana
Netcool Operations Insight
IBM Decision Optimization for Cloud Pak for Data
Tenable Nessus
IBM Power Hardware Management Console (HMC)
IBM Cloud Pak for Business Automation
OpenShift File Integrity Operator
Ansible Automation Platform
Red Hat Advanced Cluster Security for Kubernetes
IBM TXSeries for Multiplatforms
Guardium Data Security Center (GDSC)
DataStage on Cloud Pak for Data
WatsonX BI Assistant
IBM Security Verify Directory
Robotic Process Automation for Cloud Pak
Business Automation Insights
IBM Edge Application Manager
Traffix SDC
Nessus Network Monitor
Red Hat OpenShift Container Platform
LANTIME Operating System Firmware (LTOS)
IBM Qradar SIEM
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
openEuler
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libxml2 (Red Hat package)
libxml2
libxml2-devel
python3-libxml2
python2-libxml2
libxml2-debuginfo
libxml2-debugsource
libxml2-help
libxml2-debugsource (Red Hat package)
libxml2-debuginfo (Red Hat package)
python3-libxml2-debuginfo (Red Hat package)
libxml2-static (Red Hat package)
Red Hat OpenShift Serverless
OpenShift API for Data Protection (OADP)
Red Hat Ceph Storage
IBM CICS TX Advanced
IBM CICS TX Standard

How to mitigate CVE-2025-49794

Install updates from vendor's website.

IBM Observability with Instana - update to 1.0.309
Netcool Operations Insight - update to 1.6.15
Guardium Data Security Center (GDSC) - update to 3.8.5
IBM Decision Optimization for Cloud Pak for Data - update to 5.2.1
DataStage on Cloud Pak for Data - update to 5.2.1
WatsonX BI Assistant - update to 5.2.1
Nessus Network Monitor - update to 6.5.3
LANTIME Operating System Firmware (LTOS) - update to 7.10.004
IBM Qradar SIEM - update to 7.5.0 Update Pack 13 IF01
IBM Security Verify Directory - update to 10.0.4.0.1
Tenable Nessus - addressed in versions 10.8.0, 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5, 10.8.6, 10.9.6, 10.11.1
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1060.0 SP2, 11.1.1110.0
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.4, 30.0.0
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
Red Hat OpenShift Serverless - update to 1
OpenShift File Integrity Operator - update to 1.3.7
OpenShift API for Data Protection (OADP) - update to 1.4.5
Ansible Automation Platform - update to 2.5
libxml2 (Red Hat package) - addressed in versions 2.9.1-6.el7_9.10, 2.9.7-9.el8_2.3, 2.9.7-9.el8_4.6, 2.9.7-13.el8_6.10, 2.9.7-16.el8_8.9, 2.9.7-21.el8_10.1, 2.9.13-1.el9_0.5, 2.9.13-3.el9_2.7, 2.9.13-10.el9_4, 2.9.13-10.el9_6
libxml2 - update to 2.9.7-21.0.1
libxml2-devel - update to 2.9.7-21.0.1
python3-libxml2 - update to 2.9.7-21.0.1
python2-libxml2 - update to 2.9.10-48
libxml2 - addressed in versions 2.9.10-48, 2.9.14-19, 2.9.14-20, 2.11.5-8, 2.11.9-5
libxml2-debuginfo - addressed in versions 2.9.10-48, 2.9.14-19, 2.9.14-20, 2.11.5-8, 2.11.9-5
libxml2-debugsource - addressed in versions 2.9.10-48, 2.9.14-19, 2.9.14-20, 2.11.5-8, 2.11.9-5
libxml2-devel - addressed in versions 2.9.10-48, 2.9.14-19, 2.9.14-20, 2.11.5-8, 2.11.9-5
python3-libxml2 - addressed in versions 2.9.10-48, 2.9.14-19, 2.9.14-20, 2.11.5-8, 2.11.9-5
libxml2-help - addressed in versions 2.9.10-48, 2.9.14-19, 2.9.14-20, 2.11.5-8, 2.11.9-5
libxml2-debugsource (Red Hat package) - update to 2.12.5-7.el10_0
libxml2-debuginfo (Red Hat package) - update to 2.12.5-7.el10_0
python3-libxml2-debuginfo (Red Hat package) - update to 2.12.5-7.el10_0
libxml2-static (Red Hat package) - update to 2.12.5-7.el10_0
Red Hat Advanced Cluster Security for Kubernetes - update to 4.7.5
Red Hat OpenShift Container Platform - addressed in versions 4.12.82, 4.13.61, 4.14.54, 4.14.55, 4.14.58, 4.15.56, 4.16.46, 4.17.37, 4.17.42, 4.18.22, 4.18.27, 4.19.7, 4.19.17, 4.20.0
Red Hat Ceph Storage - update to 7.1
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix9
IBM CICS TX Advanced - update to 11.1.0.0 ifix33
IBM CICS TX Standard - update to 11.1.0.0 ifix34

External References

Related Security Bulletins