CVE-2025-6021
published 2025-06-12CVE-2025-6021: A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.07%
61.0th percentile
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
Affected
86 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libxml2 | < libxml2 2.9.14+dfsg-1.3~deb12u3 (bookworm) | libxml2 2.9.14+dfsg-1.3~deb12u3 (bookworm) |
| msrc | azl3_libxml2_2.11.5-6_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libxml2_2.10.4-8_on_cbl_mariner_2.0 | — | — |
| msrc | cm2_libxml2_2.10.4-8_on_cbl_mariner_2.0 | — | — |
| nokogiri | nokogiri | >= 0 < 1.18.9 | 1.18.9 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa9.1CRITICAL
osv9.1CRITICAL
vendor_ubuntu9.1CRITICAL
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_oracle5.9HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Java SE Risk Matrix: JavaFX (libxml2) — CVE-2025-6021
vendor_oracle·2026-01-15·CVSS 5.9
CVE-2025-6021 [HIGH] Oracle Oracle Java SE Risk Matrix: JavaFX (libxml2) — CVE-2025-6021
Oracle Oracle Java SE Risk Matrix: JavaFX (libxml2) vulnerability
CVE: CVE-2025-6021
CVSS: 5.9
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
CISA ICS
Hitachi Energy RTU500 Series
cisa_ics·2025-09-16·CVSS 7.5
[HIGH] Hitachi Energy RTU500 Series
ICS Advisory
##
Hitachi Energy RTU500 Series
Release DateSeptember 16, 2025
Alert CodeICSA-25-259-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.2
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: RTU500 series
- Vulnerabilities: NULL Pointer Dereference, Improper Validation of Integrity Check Value, Improper Restriction of XML External Entity Reference, Heap-based Buffer Overflow, Integer Overflow or Wraparound, Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion'), Stack-based Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could cause a Denial-of-Servi
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2025-08-14·CVSS 9.1
CVE-2025-6021 [CRITICAL] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: Several security issues were fixed in libxml2.
Ahmed Lekssays discovered that libxml2 did not properly perform certain
mathematical operations, leading to an integer overflow. An attacker
could possibly use this issue to cause a crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2025-6021)
Ahmed Lekssays discovered that libxml2 did not properly validate the size
of an untrusted input stream. An attacker could possibly use this issue
to cause a crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-6170)
Nikita Sveshnikov discovered that libxml2 did not properly handle certain
XPath expressions, leading to a use-after-free vulnerability. An attacker
could potentially exploit this issue
Red Hat
libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2
vendor_redhat·2025-06-12·CVSS 7.5
CVE-2025-6021 [HIGH] CWE-787 libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2
libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
Statement: This vulnerability is rated Moderate due to the lack of confidentiality impact and limited integrity concerns, with the main risk being potential denial-of-service from a crash. Exploitation requires crafted
Microsoft
Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2
vendor_msrc·2025-06-10·CVSS 7.5
CVE-2025-6021 [HIGH] CWE-121 Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2
Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner R
Debian
CVE-2025-6021: libxml2 - A flaw was found in libxml2's xmlBuildQName function, where integer overflows in...
vendor_debian·2025·CVSS 7.5
CVE-2025-6021 [HIGH] CVE-2025-6021: libxml2 - A flaw was found in libxml2's xmlBuildQName function, where integer overflows in...
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
Scope: local
bookworm: resolved (fixed in 2.9.14+dfsg-1.3~deb12u3)
bullseye: resolved (fixed in 2.9.10+dfsg-6.7+deb11u8)
forky: resolved (fixed in 2.12.7+dfsg+really2.9.14-2)
sid: resolved (fixed in 2.12.7+dfsg+really2.9.14-2)
trixie: resolved (fixed in 2.12.7+dfsg+really2.9.14-2)
OSV
libxml2 vulnerabilities
osv·2025-08-14·CVSS 9.1
CVE-2025-6021 [CRITICAL] libxml2 vulnerabilities
libxml2 vulnerabilities
Ahmed Lekssays discovered that libxml2 did not properly perform certain
mathematical operations, leading to an integer overflow. An attacker
could possibly use this issue to cause a crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2025-6021)
Ahmed Lekssays discovered that libxml2 did not properly validate the size
of an untrusted input stream. An attacker could possibly use this issue
to cause a crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-6170)
Nikita Sveshnikov discovered that libxml2 did not properly handle certain
XPath expressions, leading to a use-after-free vulnerability. An attacker
could potentially exploit this issue to cause a denial of service.
(CVE-2025-49794)
Nikita Sveshnik
OSV
Nokogiri patches vendored libxml2 to resolve multiple CVEs
osv·2025-07-21·CVSS 9.1
CVE-2025-6021 [CRITICAL] Nokogiri patches vendored libxml2 to resolve multiple CVEs
Nokogiri patches vendored libxml2 to resolve multiple CVEs
## Summary
Nokogiri v1.18.9 patches the vendored libxml2 to address CVE-2025-6021, CVE-2025-6170, CVE-2025-49794, CVE-2025-49795, and CVE-2025-49796.
## Impact and severity
### CVE-2025-6021
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
NVD claims a severity of 7.5 High (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Fixed by applying https://gitlab.gnome.org/GNOME/libxml2/-/commit/17d950ae
### CVE-2025-6170
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user input
GHSA
Nokogiri patches vendored libxml2 to resolve multiple CVEs
ghsa·2025-07-21·CVSS 9.1
CVE-2025-6021 [CRITICAL] Nokogiri patches vendored libxml2 to resolve multiple CVEs
Nokogiri patches vendored libxml2 to resolve multiple CVEs
## Summary
Nokogiri v1.18.9 patches the vendored libxml2 to address CVE-2025-6021, CVE-2025-6170, CVE-2025-49794, CVE-2025-49795, and CVE-2025-49796.
## Impact and severity
### CVE-2025-6021
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
NVD claims a severity of 7.5 High (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Fixed by applying https://gitlab.gnome.org/GNOME/libxml2/-/commit/17d950ae
### CVE-2025-6170
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user input
GHSA
GHSA-32vr-5hxf-x93f: A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow
ghsa_unreviewed·2025-06-12
CVE-2025-6021 [HIGH] CWE-121 GHSA-32vr-5hxf-x93f: A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
OSV
CVE-2025-6021: A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow
osv·2025-06-12·CVSS 7.5
CVE-2025-6021 [HIGH] CVE-2025-6021: A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-6021 libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2
bugzilla·2025-06-12·CVSS 7.5
CVE-2025-6021 [HIGH] CVE-2025-6021 libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2
CVE-2025-6021 libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2
Integer Overflow (Wraparound) vulnerability in the xmlBuildQName() function in libxml2. The flaw arises due to unsafe arithmetic when concatenating XML name components using the lengths of prefix and local name. These lengths, originally size_t, are cast to int, leading to incorrect calculations when values are large. If exploited, the function can perform a memcpy with an extremely large size, causing a stack buffer overflow. This vulnerability is remotely exploitable if the attacker can influence XML content passed to affected applications, potentially resulting in denial of service.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via
Bugzilla
CVE-2025-6021 pcem: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 [fedora-42]
bugzilla·2025-06-12·CVSS 7.5
CVE-2025-6021 [HIGH] CVE-2025-6021 pcem: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 [fedora-42]
CVE-2025-6021 pcem: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2372406
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with
Bugzilla
CVE-2025-6021 qt5-qtwebengine: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 [fedora-42]
bugzilla·2025-06-12·CVSS 7.5
CVE-2025-6021 [HIGH] CVE-2025-6021 qt5-qtwebengine: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 [fedora-42]
CVE-2025-6021 qt5-qtwebengine: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2372406
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains
Bugzilla
CVE-2025-6021 mingw-libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 [fedora-42]
bugzilla·2025-06-12·CVSS 7.5
CVE-2025-6021 [HIGH] CVE-2025-6021 mingw-libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 [fedora-42]
CVE-2025-6021 mingw-libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2372406
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains o
Bugzilla
CVE-2025-6021 libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 [fedora-42]
bugzilla·2025-06-12·CVSS 7.5
CVE-2025-6021 [HIGH] CVE-2025-6021 libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 [fedora-42]
CVE-2025-6021 libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2372406
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open wi
Tenable
[R1] Nessus Version 10.8.5 Fixes Multiple Vulnerabilities
blogs_tenable·2025-06-30
[R1] Nessus Version 10.8.5 Fixes Multiple Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
arXiv
Bridging Code Property Graphs and Language Models for Program Analysis
arxiv_cs_cr·2026-03-25·CVSS 7.5
[HIGH] Bridging Code Property Graphs and Language Models for Program Analysis
Bridging Code Property Graphs and Language Models for Program Analysis
Large Language Models (LLMs) face critical challenges when analyzing security vulnerabilities in real world codebases: token limits prevent loading entire repositories, code embeddings fail to capture inter procedural data flows, and LLMs struggle to generate complex static analysis queries. These limitations force existing approaches to operate on isolated code snippets, missing vulnerabilities that span multiple functions and files. We introduce codebadger, an open source Model Context Protocol (MCP) server that integrates Joern's Code Property Graph (CPG) engine with LLMs. Rather than requiring LLMs to generate complex CPG queries, codebadger provides high level tools for program slicing, taint tracking, data flow a
https://access.redhat.com/errata/RHSA-2025:10630https://access.redhat.com/errata/RHSA-2025:10698https://access.redhat.com/errata/RHSA-2025:10699https://access.redhat.com/errata/RHSA-2025:11580https://access.redhat.com/errata/RHSA-2025:11673https://access.redhat.com/errata/RHSA-2025:12098https://access.redhat.com/errata/RHSA-2025:12099https://access.redhat.com/errata/RHSA-2025:12199https://access.redhat.com/errata/RHSA-2025:12237https://access.redhat.com/errata/RHSA-2025:12239https://access.redhat.com/errata/RHSA-2025:12240https://access.redhat.com/errata/RHSA-2025:12241https://access.redhat.com/errata/RHSA-2025:13267https://access.redhat.com/errata/RHSA-2025:13289https://access.redhat.com/errata/RHSA-2025:13325https://access.redhat.com/errata/RHSA-2025:13335https://access.redhat.com/errata/RHSA-2025:13336https://access.redhat.com/errata/RHSA-2025:14059https://access.redhat.com/errata/RHSA-2025:14396https://access.redhat.com/errata/RHSA-2025:15308https://access.redhat.com/errata/RHSA-2025:15672https://access.redhat.com/errata/RHSA-2025:19020https://access.redhat.com/errata/RHSA-2026:7519https://access.redhat.com/security/cve/CVE-2025-6021https://bugzilla.redhat.com/show_bug.cgi?id=2372406https://gitlab.gnome.org/GNOME/libxml2/-/issues/926https://lists.debian.org/debian-lts-announce/2025/07/msg00014.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-032379.htmlhttps://gitlab.gnome.org/GNOME/libxml2/-/issues/926
2025-06-12
Published