CVE-2025-49795

Name
CVE-2025-49795
Description
A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vdb-entry https://access.redhat.com/security/cve/CVE-2025-49795
issue-tracking https://bugzilla.redhat.com/show_bug.cgi?id=2372379
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:10630
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:19020
secalert@redhat.com https://gitlab.gnome.org/GNOME/libxml2/-/issues/932
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:7519
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e https://cert-portal.siemens.com/productcert/html/ssa-253495.html

Match rules

CPE URI Source package Min version Max version

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libxml2 edge-main 2.13.9-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
libxml2 3.23-main 2.13.9-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
libxml2 3.22-main 2.13.9-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
libxml2 3.21-main 2.13.9-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed