CVE-2025-26434
published 2025-09-05CVE-2025-26434: In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution…
PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.08%
0.1th percentile
In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libxml2 | — | — |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9wrc-g27x-wrww: In libxml2, there is a possible out of bounds read due to a buffer overflow
ghsa_unreviewed·2025-09-05
CVE-2025-26434 [MEDIUM] CWE-120 GHSA-9wrc-g27x-wrww: In libxml2, there is a possible out of bounds read due to a buffer overflow
In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2025-26434: In libxml2, there is a possible out of bounds read due to a buffer overflow
osv·2025-09-05·CVSS 5.5
CVE-2025-26434 [MEDIUM] CVE-2025-26434: In libxml2, there is a possible out of bounds read due to a buffer overflow
In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Red Hat
libxml2: Libxml2 out of bounds read
vendor_redhat·2025-09-05·CVSS 5.5
CVE-2025-26434 [MEDIUM] CWE-120 libxml2: Libxml2 out of bounds read
libxml2: Libxml2 out of bounds read
In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
An out of bounds read flaw has been discovered in libxml2. This flaw could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: libxml2 (Red Hat Enterprise Linux 10) - Not affected
Package: libxml2 (Re
Debian
CVE-2025-26434: libxml2 - In libxml2, there is a possible out of bounds read due to a buffer overflow. Thi...
vendor_debian·2025·CVSS 5.5
CVE-2025-26434 [MEDIUM] CVE-2025-26434: libxml2 - In libxml2, there is a possible out of bounds read due to a buffer overflow. Thi...
In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
2025-09-05
Published