#VU117630 Infinite loop in Libxml2 - CVE-2025-8732
Published: October 24, 2025
Libxml2
Gnome Development Team
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the xmlParseSGMLCatalog() function in catalog.c when parsing untrusted SGML catalogs. A remote attacker can trick the victim into passing a specially crafted SGML catalogs to the application and perform a denial of service (DoS) attack.
Remediation
External links
- https://drive.google.com/file/d/1woIeYVcSQB_NwfEhaVnX6MedpWJ_nqWl/view?usp=drive_link
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/958
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/958#note_2505853
- https://vuldb.com/?ctiid.319228
- https://vuldb.com/?id.319228
- https://vuldb.com/?submit.622285
- https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/337/diffs?commit_id=a01168d3e06a1fa96733c939dbcfa5f5b5f77288