CVE-2025-27113
published 2025-02-18CVE-2025-27113: libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.01%
59.7th percentile
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.4_and_ipados | — | — |
| apple | ipados | — | — |
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_ventura | — | — |
| apple | tvos | — | — |
| apple | visionos | — | — |
| apple | watchos | — | — |
| debian | libxml2 | < libxml2 2.9.14+dfsg-1.3~deb12u2 (bookworm) | libxml2 2.9.14+dfsg-1.3~deb12u2 (bookworm) |
| msrc | azl3_libxml2_2.11.5-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_libxml2_2.11.5-5_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libxml2_2.10.4-6_on_cbl_mariner_2.0 | — | — |
| xmlsoft | libxml2 | < 2.12.10 | 2.12.10 |
| xmlsoft | libxml2 | >= 0 < 2.9.10+dfsg-6.7+deb11u6 | 2.9.10+dfsg-6.7+deb11u6 |
| xmlsoft | libxml2 | >= 0 < 2.9.14+dfsg-1.3~deb12u2 | 2.9.14+dfsg-1.3~deb12u2 |
| xmlsoft | libxml2 | >= 0 < 2.12.7+dfsg+really2.9.14-0.4 | 2.12.7+dfsg+really2.9.14-0.4 |
| xmlsoft | libxml2 | >= 0 < 2.12.7+dfsg+really2.9.14-0.4 | 2.12.7+dfsg+really2.9.14-0.4 |
| xmlsoft | libxml2 | >= 0 < 2.9.10+dfsg-5ubuntu0.20.04.9 | 2.9.10+dfsg-5ubuntu0.20.04.9 |
| xmlsoft | libxml2 | >= 0 < 2.9.13+dfsg-1ubuntu0.6 | 2.9.13+dfsg-1ubuntu0.6 |
| xmlsoft | libxml2 | >= 0 < 2.9.14+dfsg-1.3ubuntu3.2 | 2.9.14+dfsg-1.3ubuntu3.2 |
| xmlsoft | libxml2 | >= 0 < 2.9.1+dfsg1-3ubuntu4.13+esm7 | 2.9.1+dfsg1-3ubuntu4.13+esm7 |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1ubuntu0.7+esm7 | 2.9.3+dfsg1-1ubuntu0.7+esm7 |
| xmlsoft | libxml2 | >= 0 < 2.9.4+dfsg1-6.1ubuntu1.9+esm2 | 2.9.4+dfsg1-6.1ubuntu1.9+esm2 |
| xmlsoft | libxml2 | >= 2.13.0 < 2.13.6 | 2.13.6 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu8.1HIGH
vendor_oracle7.8LOW
vendor_debian2.9LOW
vendor_msrc2.9LOW
vendor_redhat2.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: ATS Framework (libxml2) — CVE-2025-27113
vendor_oracle·2025-07-15·CVSS 7.8
CVE-2025-27113 [LOW] Oracle Oracle Communications Risk Matrix: ATS Framework (libxml2) — CVE-2025-27113
Oracle Oracle Communications Risk Matrix: ATS Framework (libxml2) vulnerability
CVE: CVE-2025-27113
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2025 (JUL 2025)
Apple
CVE-2025-27113: watchOS 11.4
vendor_apple·2025-04-01·CVSS 2.9
CVE-2025-27113 [LOW] CVE-2025-27113: watchOS 11.4
Apple Security Update: About the security content of watchOS 11.4
Product: watchOS
Version: 11.4
CVE: CVE-2025-27113
Component: CVE-2025-27113
Apple
CVE-2025-27113: visionOS 2.4
vendor_apple·2025-03-31·CVSS 2.9
CVE-2025-27113 [LOW] CVE-2025-27113: visionOS 2.4
Apple Security Update: About the security content of visionOS 2.4
Product: visionOS
Version: 2.4
CVE: CVE-2025-27113
Component: CVE-2025-27113
Apple
CVE-2025-27113: iOS 18.4 and iPadOS 18.4
vendor_apple·2025-03-31·CVSS 2.9
CVE-2025-27113 [LOW] CVE-2025-27113: iOS 18.4 and iPadOS 18.4
Apple Security Update: About the security content of iOS 18.4 and iPadOS 18.4
Product: iOS 18.4 and iPadOS
Version: 18.4
CVE: CVE-2025-27113
Component: CVE-2025-27113
Apple
CVE-2025-27113: macOS Sequoia 15.4
vendor_apple·2025-03-31·CVSS 2.9
CVE-2025-27113 [LOW] CVE-2025-27113: macOS Sequoia 15.4
Apple Security Update: About the security content of macOS Sequoia 15.4
Product: macOS Sequoia
Version: 15.4
CVE: CVE-2025-27113
Component: CVE-2025-27113
Apple
CVE-2025-27113: tvOS 18.4
vendor_apple·2025-03-31·CVSS 2.9
CVE-2025-27113 [LOW] CVE-2025-27113: tvOS 18.4
Apple Security Update: About the security content of tvOS 18.4
Product: tvOS
Version: 18.4
CVE: CVE-2025-27113
Component: CVE-2025-27113
Apple
CVE-2025-27113: macOS Sonoma 14.7.5
vendor_apple·2025-03-31·CVSS 2.9
CVE-2025-27113 [LOW] CVE-2025-27113: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-27113
Component: CVE-2025-27113
Apple
CVE-2025-27113: iPadOS 17.7.6
vendor_apple·2025-03-31·CVSS 2.9
CVE-2025-27113 [LOW] CVE-2025-27113: iPadOS 17.7.6
Apple Security Update: About the security content of iPadOS 17.7.6
Product: iPadOS
Version: 17.7.6
CVE: CVE-2025-27113
Component: CVE-2025-27113
Apple
CVE-2025-27113: macOS Ventura 13.7.5
vendor_apple·2025-03-31·CVSS 2.9
CVE-2025-27113 [LOW] CVE-2025-27113: macOS Ventura 13.7.5
Apple Security Update: About the security content of macOS Ventura 13.7.5
Product: macOS Ventura
Version: 13.7.5
CVE: CVE-2025-27113
Component: CVE-2025-27113
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2025-02-25·CVSS 8.1
CVE-2022-49043 [HIGH] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: Several security issues were fixed in libxml2.
It was discovered that libxml2 incorrectly handled certain memory
operations. A remote attacker could use this issue to cause libxml2 to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and
Ubuntu 18.04 LTS. (CVE-2022-49043)
It was discovered that the libxml2 xmllint tool incorrectly handled
certain memory operations. If a user or automated system were tricked into
running xmllint on a specially crafted xml file, a remote attacker could
cause xmllint to crash, resulting in a denial of service. This issue only
affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
(CVE-2024-34459)
It was discovered tha
Red Hat
libxml2: NULL Pointer Dereference in libxml2 xmlPatMatch
vendor_redhat·2025-02-18·CVSS 2.9
CVE-2025-27113 [LOW] CWE-476 libxml2: NULL Pointer Dereference in libxml2 xmlPatMatch
libxml2: NULL Pointer Dereference in libxml2 xmlPatMatch
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.
A flaw was found in libxml2. This vulnerability allows a NULL pointer dereference, leading to a potential crash or denial of service via a crafted XML pattern.
Statement: Because this vulnerability requires that an unsuspecting user parses a specially crafted malicious XML file, or that a service that does so accepts untrusted input, and because the consequences of this flaw are limited to exhaustion of the resources available to the user with whose privileges the vulnerable application is run, Red Hat assesses this vulnerability's impact as Low.
Mitigation: Mitigation for this issue is either not available or the currently
Microsoft
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.
vendor_msrc·2025-02-11·CVSS 2.9
CVE-2025-27113 [LOW] CWE-476 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Remedia
Debian
CVE-2025-27113: libxml2 - libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference i...
vendor_debian·2025·CVSS 2.9
CVE-2025-27113 [LOW] CVE-2025-27113: libxml2 - libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference i...
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.
Scope: local
bookworm: resolved (fixed in 2.9.14+dfsg-1.3~deb12u2)
bullseye: resolved (fixed in 2.9.10+dfsg-6.7+deb11u6)
forky: resolved (fixed in 2.12.7+dfsg+really2.9.14-0.4)
sid: resolved (fixed in 2.12.7+dfsg+really2.9.14-0.4)
trixie: resolved (fixed in 2.12.7+dfsg+really2.9.14-0.4)
OSV
libxml2 vulnerabilities
osv·2025-02-25·CVSS 7.8
CVE-2022-49043 [HIGH] libxml2 vulnerabilities
libxml2 vulnerabilities
It was discovered that libxml2 incorrectly handled certain memory
operations. A remote attacker could use this issue to cause libxml2 to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and
Ubuntu 18.04 LTS. (CVE-2022-49043)
It was discovered that the libxml2 xmllint tool incorrectly handled
certain memory operations. If a user or automated system were tricked into
running xmllint on a specially crafted xml file, a remote attacker could
cause xmllint to crash, resulting in a denial of service. This issue only
affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
(CVE-2024-34459)
It was discovered that libxml2 did not properly manage memory. An attacker
could poss
GHSA
GHSA-m9m6-wcr9-hh75: libxml2 before 2
ghsa_unreviewed·2025-02-19
CVE-2025-27113 [LOW] CWE-476 GHSA-m9m6-wcr9-hh75: libxml2 before 2
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.
OSV
CVE-2025-27113: libxml2 before 2
osv·2025-02-18·CVSS 7.5
CVE-2025-27113 [HIGH] CVE-2025-27113: libxml2 before 2
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.
No detection rules found.
No public exploits indexed.
https://gitlab.gnome.org/GNOME/libxml2/-/issues/861http://seclists.org/fulldisclosure/2025/Apr/10http://seclists.org/fulldisclosure/2025/Apr/11http://seclists.org/fulldisclosure/2025/Apr/12http://seclists.org/fulldisclosure/2025/Apr/13http://seclists.org/fulldisclosure/2025/Apr/4http://seclists.org/fulldisclosure/2025/Apr/5http://seclists.org/fulldisclosure/2025/Apr/8http://seclists.org/fulldisclosure/2025/Apr/9https://lists.debian.org/debian-lts-announce/2025/02/msg00028.htmlhttps://security.netapp.com/advisory/ntap-20250306-0004/
2025-02-18
Published