CVE-2025-49795

EUVD-2025-18416
A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
Debian logo
Debian Releases
Debian Product
Codename
libxml2
bookworm
2.9.14+dfsg-1.3~deb12u5
fixed
bookworm (security)
2.9.14+dfsg-1.3~deb12u4
fixed
bullseye
2.9.10+dfsg-6.7+deb11u4
fixed
bullseye (security)
2.9.10+dfsg-6.7+deb11u9
fixed
forky
2.15.2+dfsg-0.1
fixed
sid
2.15.2+dfsg-0.1
fixed
trixie
2.12.7+dfsg+really2.9.14-2.1+deb13u2
fixed
trixie (security)
2.12.7+dfsg+really2.9.14-2.1+deb13u1
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libxml2-2
suse enterprise desktop 15 SP6
2.10.3-150500.5.29.1
fixed
suse enterprise desktop 15 SP7
2.12.10-150700.4.3.1
fixed
suse enterprise sap 15 SP6
2.10.3-150500.5.29.1
fixed
suse enterprise sap 15 SP7
2.12.10-150700.4.3.1
fixed
suse enterprise server 15 SP5
2.10.3-150500.5.29.1
fixed
suse enterprise server 15 SP6
2.10.3-150500.5.29.1
fixed
suse enterprise server 15 SP7
2.12.10-150700.4.3.1
fixed
libxml2-2-32bit
suse enterprise desktop 15 SP6
2.10.3-150500.5.29.1
fixed
suse enterprise desktop 15 SP7
2.12.10-150700.4.3.1
fixed
suse enterprise sap 15 SP6
2.10.3-150500.5.29.1
fixed
suse enterprise sap 15 SP7
2.12.10-150700.4.3.1
fixed
suse enterprise server 15 SP5
2.10.3-150500.5.29.1
fixed
suse enterprise server 15 SP6
2.10.3-150500.5.29.1
fixed
suse enterprise server 15 SP7
2.12.10-150700.4.3.1
fixed
libxml2-devel
suse enterprise desktop 15 SP6
2.10.3-150500.5.29.1
fixed
suse enterprise desktop 15 SP7
2.12.10-150700.4.3.1
fixed
suse enterprise sap 15 SP6
2.10.3-150500.5.29.1
fixed
suse enterprise sap 15 SP7
2.12.10-150700.4.3.1
fixed
suse enterprise server 15 SP5
2.10.3-150500.5.29.1
fixed
suse enterprise server 15 SP6
2.10.3-150500.5.29.1
fixed
suse enterprise server 15 SP7
2.12.10-150700.4.3.1
fixed
libxml2-tools
suse enterprise desktop 15 SP6
2.10.3-150500.5.29.1
fixed
suse enterprise desktop 15 SP7
2.12.10-150700.4.3.1
fixed
suse enterprise sap 15 SP6
2.10.3-150500.5.29.1
fixed
suse enterprise sap 15 SP7
2.12.10-150700.4.3.1
fixed
suse enterprise server 15 SP5
2.10.3-150500.5.29.1
fixed
suse enterprise server 15 SP6
2.10.3-150500.5.29.1
fixed
suse enterprise server 15 SP7
2.12.10-150700.4.3.1
fixed
python3-libxml2
suse enterprise desktop 15 SP6
2.10.3-150500.5.29.1
fixed
suse enterprise desktop 15 SP7
2.12.10-150700.4.3.1
fixed
suse enterprise sap 15 SP6
2.10.3-150500.5.29.1
fixed
suse enterprise sap 15 SP7
2.12.10-150700.4.3.1
fixed
suse enterprise server 15 SP5
2.10.3-150500.5.29.1
fixed
suse enterprise server 15 SP6
2.10.3-150500.5.29.1
fixed
suse enterprise server 15 SP7
2.12.10-150700.4.3.1
fixed
python311-libxml2
suse enterprise server 15 SP5
2.10.3-150500.5.29.1
fixed