CVE-2024-25062
Published: February 5, 2024Last modified: July 22, 2025
Description
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 7.5 |
| Attack Vector | NETWORK |
| Attack complexity | LOW |
| Privileges required | NONE |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | NONE |
| Integrity impact | NONE |
| Availability impact | HIGH |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | libxml2 | Fixed (2.10.4-r1) |
| Stream | libxml2 | Fixed (2.12.5-r0) | |
| Hardened Containers | 23 LTS | libxml2 | Fixed (2.10.4-r1) |
| Stream | libxml2 | Fixed (2.12.5-r0) | |
| Liberica JDK | 8 | jdk-full | Fixed (8u432+7) |
| jre-full | Fixed (8u432+7) | ||
| 11 | jdk-full | Fixed (11.0.25+11) | |
| jre-full | Fixed (11.0.25+11) | ||
| 17 | jdk-full | Fixed (17.0.13+12) | |
| jre-full | Fixed (17.0.13+12) | ||
| 21 | jdk-full | Fixed (21.0.5+11) | |
| jre-full | Fixed (21.0.5+11) | ||
| 23 | jdk-full | Fixed (23.0.1+13) | |
| jre-full | Fixed (23.0.1+13) | ||
| Liberica NIK | 23 (JDK 17) | full | Fixed (23.0.6+1) |
| 23 (JDK 21) | full | Fixed (23.1.5+1) | |
| 24 (JDK 23) | full | Fixed (24.1.1+1) |