CLSA-2025-1757413554

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2025-1757413554.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2025-1757413554
Upstream
Published
2025-09-09T10:25:58Z
Modified
2026-06-01T00:33:27.587911851Z
Summary
libxml2: Fix of 2 CVEs
Details
  • CVE-2025-7425: fix heap-use-after-free in xmlFreeID caused by 'atype' corruption
  • CVE-2025-6021: fix integer overflows in buffer size calculations
References

Affected packages

TuxCare:RHEL:7 / libxml2

Package

Name
libxml2
Purl
pkg:rpm/tuxcare/libxml2?distro=rhel-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.9.1-6.0.3.el7_9.6.tuxcare.els7

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2025-1757413554.json"

TuxCare:RHEL:7 / libxml2-devel

Package

Name
libxml2-devel
Purl
pkg:rpm/tuxcare/libxml2-devel?distro=rhel-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.9.1-6.0.3.el7_9.6.tuxcare.els7

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2025-1757413554.json"

TuxCare:RHEL:7 / libxml2-python

Package

Name
libxml2-python
Purl
pkg:rpm/tuxcare/libxml2-python?distro=rhel-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.9.1-6.0.3.el7_9.6.tuxcare.els7

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2025-1757413554.json"

TuxCare:RHEL:7 / libxml2-static

Package

Name
libxml2-static
Purl
pkg:rpm/tuxcare/libxml2-static?distro=rhel-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.9.1-6.0.3.el7_9.6.tuxcare.els7

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/rhel7els/CLSA-2025-1757413554.json"