Disclosure summary
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
Source-reported weakness categories
CWE-121
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2025-6170
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| redhat | jboss_core_services | - |
| redhat | openshift_container_platform | 4.0 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
| xmlsoft | libxml2 | - |
Microsoft Security Updates (CVRF) · 2025-Jun
Open original source · Updated Feb 17, 2026
Libxml2: stack buffer overflow in xmllint interactive shell command handling
Maximum of vendor-reported product scores; products and fixed builds are associations, not a universal affected-version statement.
Microsoft maximum product score: 2.5
| Vendor | Product / association | Version / bounds |
|---|---|---|
| Microsoft update guide | cm2 libxml2 2.10.4-8 on CBL Mariner 2.0 | (MSRC status code 3) |
| Microsoft update guide | azl3 libxml2 2.11.5-6 on Azure Linux 3.0 | (MSRC status code 3) |
| Microsoft update guide | cbl2 libxml2 2.10.4-8 on CBL Mariner 2.0 | (MSRC status code 3) |
Vendor remediation references
- CBL-Mariner Releases · build 2.10.4-8 · product IDs 19569-16823, 20212-17086
- Vendor guidance · product IDs 19569-16823, 20212-17086
- CBL-Mariner Releases · build 2.11.5-6 · product IDs 19618-17084
- Vendor guidance · product IDs 19618-17084
Original records & references
- NIST NVD record
- CVE Program record
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com — Mitigation, Third Party Advisory
- bugzilla.redhat.com — Issue Tracking, Third Party Advisory
- gitlab.gnome.org
- lists.debian.org
- cert-portal.siemens.com
PUBLISHED 2025-06-16T12:15:20-04:00
MODIFIED 2026-10-08T09:17:10-04:00
INGESTED 2026-10-08T12:30:36-04:00