CVE-2025-6170
published 2025-06-16CVE-2025-6170: A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program…
PriorityP410low2.5CVSS 3.1
AVLACHPRNUIRSUCNINAL
EPSS
0.20%
10.3th percentile
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libxml2 | < libxml2 2.9.14+dfsg-1.3~deb12u3 (bookworm) | libxml2 2.9.14+dfsg-1.3~deb12u3 (bookworm) |
| msrc | azl3_libxml2_2.11.5-6_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libxml2_2.10.4-8_on_cbl_mariner_2.0 | — | — |
| msrc | cm2_libxml2_2.10.4-8_on_cbl_mariner_2.0 | — | — |
| nokogiri | nokogiri | >= 0 < 1.18.9 | 1.18.9 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
| xmlsoft | libxml2 | >= 0 < 2.9.10+dfsg-6.7+deb11u8 | 2.9.10+dfsg-6.7+deb11u8 |
| xmlsoft | libxml2 | >= 0 < 2.9.14+dfsg-1.3~deb12u3 | 2.9.14+dfsg-1.3~deb12u3 |
| xmlsoft | libxml2 | >= 0 < 2.12.7+dfsg+really2.9.14-2.1 | 2.12.7+dfsg+really2.9.14-2.1 |
| xmlsoft | libxml2 | >= 0 < 2.12.7+dfsg+really2.9.14-2.1 | 2.12.7+dfsg+really2.9.14-2.1 |
| xmlsoft | libxml2 | >= 0 < 2.9.13+dfsg-1ubuntu0.8 | 2.9.13+dfsg-1ubuntu0.8 |
| xmlsoft | libxml2 | >= 0 < 2.9.14+dfsg-1.3ubuntu3.4 | 2.9.14+dfsg-1.3ubuntu3.4 |
| xmlsoft | libxml2 | >= 0 < 2.9.1+dfsg1-3ubuntu4.13+esm8 | 2.9.1+dfsg1-3ubuntu4.13+esm8 |
| xmlsoft | libxml2 | >= 0 < 2.9.3+dfsg1-1ubuntu0.7+esm9 | 2.9.3+dfsg1-1ubuntu0.7+esm9 |
| xmlsoft | libxml2 | >= 0 < 2.9.4+dfsg1-6.1ubuntu1.9+esm4 | 2.9.4+dfsg1-6.1ubuntu1.9+esm4 |
| xmlsoft | libxml2 | >= 0 < 2.9.10+dfsg-5ubuntu0.20.04.10+esm1 | 2.9.10+dfsg-5ubuntu0.20.04.10+esm1 |
CVSS provenance
nvdv3.12.5LOWCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
ghsa9.1CRITICAL
osv9.1CRITICAL
vendor_ubuntu9.1CRITICAL
vendor_debian2.5LOW
vendor_msrc2.5LOW
vendor_redhat2.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2025-08-14·CVSS 9.1
CVE-2025-6021 [CRITICAL] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: Several security issues were fixed in libxml2.
Ahmed Lekssays discovered that libxml2 did not properly perform certain
mathematical operations, leading to an integer overflow. An attacker
could possibly use this issue to cause a crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2025-6021)
Ahmed Lekssays discovered that libxml2 did not properly validate the size
of an untrusted input stream. An attacker could possibly use this issue
to cause a crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-6170)
Nikita Sveshnikov discovered that libxml2 did not properly handle certain
XPath expressions, leading to a use-after-free vulnerability. An attacker
could potentially exploit this issue
Red Hat
libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling
vendor_redhat·2025-06-16·CVSS 2.5
CVE-2025-6170 [LOW] CWE-121 libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling
libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
Statement: The Red Hat Product Security team has rated t
Microsoft
Libxml2: stack buffer overflow in xmllint interactive shell command handling
vendor_msrc·2025-06-10·CVSS 2.5
CVE-2025-6170 [LOW] CWE-121 Libxml2: stack buffer overflow in xmllint interactive shell command handling
Libxml2: stack buffer overflow in xmllint interactive shell command handling
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
R
Debian
CVE-2025-6170: libxml2 - A flaw was found in the interactive shell of the xmllint command-line tool, used...
vendor_debian·2025·CVSS 2.5
CVE-2025-6170 [LOW] CVE-2025-6170: libxml2 - A flaw was found in the interactive shell of the xmllint command-line tool, used...
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
Scope: local
bookworm: resolved (fixed in 2.9.14+dfsg-1.3~deb12u3)
bullseye: resolved (fixed in 2.9.10+dfsg-6.7+deb11u8)
forky: resolved (fixed in 2.12.7+dfsg+really2.9.14-2.1)
sid: resolved (fixed in 2.12.7+dfsg+really2.9.14-2.1)
trixie: resolved (fixed in 2.12.7+dfsg+really2.9.14-2.1)
OSV
libxml2 vulnerabilities
osv·2025-08-14·CVSS 9.1
CVE-2025-6021 [CRITICAL] libxml2 vulnerabilities
libxml2 vulnerabilities
Ahmed Lekssays discovered that libxml2 did not properly perform certain
mathematical operations, leading to an integer overflow. An attacker
could possibly use this issue to cause a crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2025-6021)
Ahmed Lekssays discovered that libxml2 did not properly validate the size
of an untrusted input stream. An attacker could possibly use this issue
to cause a crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-6170)
Nikita Sveshnikov discovered that libxml2 did not properly handle certain
XPath expressions, leading to a use-after-free vulnerability. An attacker
could potentially exploit this issue to cause a denial of service.
(CVE-2025-49794)
Nikita Sveshnik
OSV
Nokogiri patches vendored libxml2 to resolve multiple CVEs
osv·2025-07-21·CVSS 9.1
CVE-2025-6021 [CRITICAL] Nokogiri patches vendored libxml2 to resolve multiple CVEs
Nokogiri patches vendored libxml2 to resolve multiple CVEs
## Summary
Nokogiri v1.18.9 patches the vendored libxml2 to address CVE-2025-6021, CVE-2025-6170, CVE-2025-49794, CVE-2025-49795, and CVE-2025-49796.
## Impact and severity
### CVE-2025-6021
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
NVD claims a severity of 7.5 High (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Fixed by applying https://gitlab.gnome.org/GNOME/libxml2/-/commit/17d950ae
### CVE-2025-6170
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user input
GHSA
Nokogiri patches vendored libxml2 to resolve multiple CVEs
ghsa·2025-07-21·CVSS 9.1
CVE-2025-6021 [CRITICAL] Nokogiri patches vendored libxml2 to resolve multiple CVEs
Nokogiri patches vendored libxml2 to resolve multiple CVEs
## Summary
Nokogiri v1.18.9 patches the vendored libxml2 to address CVE-2025-6021, CVE-2025-6170, CVE-2025-49794, CVE-2025-49795, and CVE-2025-49796.
## Impact and severity
### CVE-2025-6021
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
NVD claims a severity of 7.5 High (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Fixed by applying https://gitlab.gnome.org/GNOME/libxml2/-/commit/17d950ae
### CVE-2025-6170
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user input
GHSA
GHSA-6qrf-r65h-2r77: A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files
ghsa_unreviewed·2025-06-16
CVE-2025-6170 [LOW] CWE-121 GHSA-6qrf-r65h-2r77: A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
OSV
CVE-2025-6170: A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files
osv·2025-06-16·CVSS 2.5
CVE-2025-6170 [LOW] CVE-2025-6170: A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-6170 mingw-libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling [fedora-42]
bugzilla·2025-06-16·CVSS 2.5
CVE-2025-6170 [LOW] CVE-2025-6170 mingw-libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling [fedora-42]
CVE-2025-6170 mingw-libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2372952
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
Bugzilla
CVE-2025-6170 libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling [fedora-42]
bugzilla·2025-06-16·CVSS 2.5
CVE-2025-6170 [LOW] CVE-2025-6170 libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling [fedora-42]
CVE-2025-6170 libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2372952
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'vers
Bugzilla
CVE-2025-6170 qt5-qtwebengine: Stack Buffer Overflow in xmllint Interactive Shell Command Handling [fedora-42]
bugzilla·2025-06-16·CVSS 2.5
CVE-2025-6170 [LOW] CVE-2025-6170 qt5-qtwebengine: Stack Buffer Overflow in xmllint Interactive Shell Command Handling [fedora-42]
CVE-2025-6170 qt5-qtwebengine: Stack Buffer Overflow in xmllint Interactive Shell Command Handling [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2372952
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with
Bugzilla
CVE-2025-6170 libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling
bugzilla·2025-06-16·CVSS 2.5
CVE-2025-6170 [LOW] CVE-2025-6170 libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling
CVE-2025-6170 libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling
Stack-based buffer overflow vulnerability in the interactive shell of the xmllint tool in libxml2. The issue is caused by an unsafe use of strcpy() when processing user-supplied command-line input. When an attacker passes an overly long argument to any shell command (e.g., exit, cat, etc.), the input exceeds the fixed-size stack buffer, resulting in a crash or potentially arbitrary code execution on systems lacking stack protections.
This vulnerability affects only the interactive shell and requires that an attacker can influence or control the command input to xmllint, which is uncommon in typical deployments.
https://access.redhat.com/errata/RHSA-2026:36734https://access.redhat.com/errata/RHSA-2026:39304https://access.redhat.com/errata/RHSA-2026:39317https://access.redhat.com/errata/RHSA-2026:7519https://access.redhat.com/security/cve/CVE-2025-6170https://bugzilla.redhat.com/show_bug.cgi?id=2372952https://gitlab.gnome.org/GNOME/libxml2/-/issues/941https://lists.debian.org/debian-lts-announce/2025/07/msg00014.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-253495.html
2025-06-16
Published