RHSA-2025:10630: Important: libxml2 security update
Important: libxml2 security update
Other sources
The libxml2 library is a development toolbox providing the implementation of various XML standards.Security Fix(es): libxml: Heap use after free (UAF) leads to Denial of service (DoS) (CVE-2025-49794) libxml: Null pointer dereference leads to Denial of service (DoS) (CVE-2025-49795) libxml: Type confusion leads to Denial of service (DoS) (CVE-2025-49796) libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 (CVE-2025-6021) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:10630?
The severity of RHSA-2025:10630 is classified as high with a score of 7.
What vulnerabilities are addressed in RHSA-2025:10630?
RHSA-2025:10630 addresses a heap use after free and a null pointer dereference which can lead to Denial of Service (DoS).
How do I fix RHSA-2025:10630?
To fix RHSA-2025:10630, update the libxml2 packages as specified in the advisory.
Which software packages are impacted by RHSA-2025:10630?
The impacted software packages include redhat/libxml2, redhat/libxml2-debuginfo, and redhat/python3-libxml2.
When was RHSA-2025:10630 published?
RHSA-2025:10630 was published on July 8, 2025.