FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

libxml2 -- multiple vulnerabilities

Affected packages
libxml2 < 2.14.5
linux-c7-libxml2 < 2.14.5
linux-rl9-libxml2 < 2.14.5

Details

VuXML ID abbc8912-5efa-11f0-ae84-99047d0a6bcc
Discovery 2025-05-27
Entry 2025-07-12
Modified 2025-07-15

Alan Coopersmith reports:

As discussed in https://gitlab.gnome.org/GNOME/libxml2/-/issues/913 the security policy of libxml2 has been changed to disclose vulnerabilities before fixes are available so that people other than the maintainer can contribute to fixing security issues in this library.

As part of this, the following 5 CVE's have been disclosed recently:

(CVE-2025-49794) Heap use after free (UAF) leads to Denial of service (DoS) https://gitlab.gnome.org/GNOME/libxml2/-/issues/931 [...]

(CVE-2025-49795) Null pointer dereference leads to Denial of service (DoS) https://gitlab.gnome.org/GNOME/libxml2/-/issues/932 [...]

(CVE-2025-49796) Type confusion leads to Denial of service (DoS) https://gitlab.gnome.org/GNOME/libxml2/-/issues/933 [...]

For all three of the above, note that upstream is considering removing Schematron support completely, as discussed in https://gitlab.gnome.org/GNOME/libxml2/-/issues/935.

(CVE-2025-6021) Integer Overflow Leading to Buffer Overflow in xmlBuildQName() https://gitlab.gnome.org/GNOME/libxml2/-/issues/926 [...]

(CVE-2025-6170) Stack-based Buffer Overflow in xmllint Shell https://gitlab.gnome.org/GNOME/libxml2/-/issues/941 [...]

References

CVE Name CVE-2025-49794
CVE Name CVE-2025-49795
CVE Name CVE-2025-49795
CVE Name CVE-2025-6021
CVE Name CVE-2025-6170
URL https://gitlab.gnome.org/GNOME/libxml2/-/issues/913
URL https://gitlab.gnome.org/GNOME/libxml2/-/issues/926
URL https://gitlab.gnome.org/GNOME/libxml2/-/issues/931
URL https://gitlab.gnome.org/GNOME/libxml2/-/issues/932
URL https://gitlab.gnome.org/GNOME/libxml2/-/issues/933
URL https://gitlab.gnome.org/GNOME/libxml2/-/issues/935
URL https://gitlab.gnome.org/GNOME/libxml2/-/issues/941
URL https://gitlab.gnome.org/Teams/Releng/security/-/wikis/2025#libxml2-and-libxslt
URL https://www.openwall.com/lists/oss-security/2025/06/16/6