libxml2-2.9.1-6.6.0.4.el7.AXS7
エラータID: AXSA:2025-10716:14
This library allows to manipulate XML files. It includes support
to read, modify and write XML and HTML files. There is DTDs support
this includes parsing and validation even with complex DtDs, either
at parse time or later once the document has been modified. The output
can be a simple SAX stream or and in-memory DOM like representations.
In this case one can use the built-in XPath and XPointer implementation
to select sub nodes or ranges. A flexible Input/Output mechanism is
available, with existing HTTP and FTP modules and combined to an
URI library.
Security Fix(es):
* CVE-2025-49794: fix memory safety issues in xmlSchematronReportOutput when
parsing XPath elements
* CVE-2025-49796: fix memory corruption issue triggered by processing sch:name
elements in input XML file
CVE(s):
CVE-2025-49794
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.
CVE-2025-49796
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.
Update packages.
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.
N/A
Asianux Server 7 for x86_64
- libxml2-2.9.1-6.6.0.4.el7.AXS7.i686.rpm
MD5: 17c09f79c0ea21c9c3c0a9a76f6dfea3
SHA-256: a9f41c467dcfb5a71e68724200fbef2a0fbe87aeb7f79921f64653fc10244ebe
Size: 655.30 kB - libxml2-2.9.1-6.6.0.4.el7.AXS7.x86_64.rpm
MD5: 18b7a2d8a407f6177cbeb5ae631da5b0
SHA-256: 5ac8c9c6db7079faa9df09e28f87e421866d2d8149834c2f1f4771f79e0693be
Size: 668.80 kB - libxml2-devel-2.9.1-6.6.0.4.el7.AXS7.i686.rpm
MD5: ae887425c0ed24c7bcd0e75f56269bb8
SHA-256: 58063b251bf022ef0101a22cd704eaf6de3fb93853045076d975ae103570fe7a
Size: 1.05 MB - libxml2-devel-2.9.1-6.6.0.4.el7.AXS7.x86_64.rpm
MD5: 8fb4e09b4ae05f2055ceeaa2bd555ad8
SHA-256: a21eaffbd36fb48a57ef74f137a1ec3dbd75fe1c913ae7a060be420cf721f4bc
Size: 1.05 MB - libxml2-python-2.9.1-6.6.0.4.el7.AXS7.x86_64.rpm
MD5: f96c981e2eefab0dbd4d69ba0e1418cc
SHA-256: 78b21eeca69d20f3cf078927e3b42dbc0edfc8ce14915e65002518f1fb59ac18
Size: 248.21 kB