SUSE-SU-2025:20564-1

Source
https://www.suse.com/support/update/announcement/2025/suse-su-202520564-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:20564-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2025:20564-1
Upstream
CVE (6)
Related
Published
2025-08-21T08:01:26Z
Modified
2026-03-11T07:29:48Z
Summary
Security update for libxml2
Details

This update for libxml2 fixes the following issues:

  • CVE-2025-6021: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 [bsc#1244580]
  • CVE-2025-6170: stack buffer overflow may lead to a crash [bsc#1244700]
  • CVE-2025-7425: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr [bsc#1246296]
  • CVE-2025-49794: heap use after free (UAF) can lead to Denial of service (DoS) [bsc#1244554]
  • CVE-2025-49795: null pointer dereference may lead to Denial of service (DoS) [bsc#1244555]
  • CVE-2025-49796: type confusion may lead to Denial of service (DoS) [bsc#1244557]
References

Affected packages

SUSE:Linux Micro 6.0 / libxml2

Package

Name
libxml2
Purl
pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Micro%206.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.11.6-10.1

Ecosystem specific

{
    "binaries":  [
        {
            "libxml2-2":  "2.11.6-10.1",
            "libxml2-tools":  "2.11.6-10.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:20564-1.json"