CVE-2025-6170

Name
CVE-2025-6170
Description
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vdb-entry https://access.redhat.com/security/cve/CVE-2025-6170
issue-tracking https://bugzilla.redhat.com/show_bug.cgi?id=2372952
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/07/msg00014.html
secalert@redhat.com https://gitlab.gnome.org/GNOME/libxml2/-/issues/941
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:7519
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e https://cert-portal.siemens.com/productcert/html/ssa-253495.html
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:36734
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:39304
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:39317
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:44481
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:46836

Match rules

CPE URI Source package Min version Max version
shopxo >= 0 < 2.14.5
cpe:2.3:a:redhat:jboss_core_services:-:*:*:*:*:*:*:* jboss_core_services == None == -
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* openshift_container_platform == None == 4.0
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* enterprise_linux == None == 6.0
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* enterprise_linux == None == 7.0
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* enterprise_linux == None == 8.0
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* enterprise_linux == None == 9.0
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* enterprise_linux == None == 10.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libxml2 edge-main 2.13.9-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
libxml2 3.23-main 2.13.9-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
libxml2 3.22-main 2.13.9-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
libxml2 3.21-main 2.13.9-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed