All errata/c9f2/ALT-PU-2026-15073-3
ALT-PU-2026-15073-3

Package update libxml2 in branch c9f2

Version2.9.12-alt1.c9f2.10
Published2026-09-11
Max severityCRITICAL
Severity:

Closed issues (5)

BDU:2025-08978
CRITICAL9.1

Уязвимость функции xmlSchematronFormatReport() библиотеки libxml2, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2025-07-23Modified: 2026-05-31
CVSS 3.xCRITICAL 9.1
CVSS:3.x/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS 2.0CRITICAL 9.4
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:C/A:C
BDU:2025-08979
CRITICAL9.1

Уязвимость функции xmlSchematronGetNode библиотеки Libxml2, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2025-07-23Modified: 2026-05-31
CVSS 3.xCRITICAL 9.1
CVSS:3.x/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS 2.0CRITICAL 9.4
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:C/A:C
CVE-2025-49794
CRITICAL9.1

A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.

Published: 2025-06-16Modified: 2026-09-10
CVSS 3.xCRITICAL 9.1
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
References
CVE-2025-49796
CRITICAL9.1

A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.

Published: 2025-06-16Modified: 2026-09-10
CVSS 3.xCRITICAL 9.1
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
References