cbcvebase.
CVE-2025-27113
published 2025-02-18

CVE-2025-27113: libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.

Affected

24 ranges
VendorProductVersion rangeFixed in
appleios_18.4_and_ipados
appleipados
applemacos_sequoia
applemacos_sonoma
applemacos_ventura
appletvos
applevisionos
applewatchos
debianlibxml2< libxml2 2.9.14+dfsg-1.3~deb12u2 (bookworm)libxml2 2.9.14+dfsg-1.3~deb12u2 (bookworm)
msrcazl3_libxml2_2.11.5-4_on_azure_linux_3.0
msrcazl3_libxml2_2.11.5-5_on_azure_linux_3.0
msrccbl2_libxml2_2.10.4-6_on_cbl_mariner_2.0
xmlsoftlibxml2< 2.12.102.12.10
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.7+deb11u62.9.10+dfsg-6.7+deb11u6
xmlsoftlibxml2>= 0 < 2.9.14+dfsg-1.3~deb12u22.9.14+dfsg-1.3~deb12u2
xmlsoftlibxml2>= 0 < 2.12.7+dfsg+really2.9.14-0.42.12.7+dfsg+really2.9.14-0.4
xmlsoftlibxml2>= 0 < 2.12.7+dfsg+really2.9.14-0.42.12.7+dfsg+really2.9.14-0.4
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-5ubuntu0.20.04.92.9.10+dfsg-5ubuntu0.20.04.9
xmlsoftlibxml2>= 0 < 2.9.13+dfsg-1ubuntu0.62.9.13+dfsg-1ubuntu0.6
xmlsoftlibxml2>= 0 < 2.9.14+dfsg-1.3ubuntu3.22.9.14+dfsg-1.3ubuntu3.2
xmlsoftlibxml2>= 0 < 2.9.1+dfsg1-3ubuntu4.13+esm72.9.1+dfsg1-3ubuntu4.13+esm7
xmlsoftlibxml2>= 0 < 2.9.3+dfsg1-1ubuntu0.7+esm72.9.3+dfsg1-1ubuntu0.7+esm7
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-6.1ubuntu1.9+esm22.9.4+dfsg1-6.1ubuntu1.9+esm2
xmlsoftlibxml2>= 2.13.0 < 2.13.62.13.6

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH