boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-6021

Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0137   70.9     —
AFFECTED
  Product                                                                Versions     Fixed
  libxml2                                                                unspecified  —
  Red Hat Enterprise Linux 10                                            unspecified  0:2.12.5-7.el10_0
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:2.9.1-6.el7_9.10
  Red Hat Enterprise Linux 8                                             unspecified  0:2.9.7-21.el8_10.1
  Red Hat Enterprise Linux 8                                             unspecified  0:2.9.7-21.el8_10.1
  Red Hat Enterprise Linux 8.2 Advanced Update Support                   unspecified  0:2.9.7-9.el8_2.3
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:2.9.7-9.el8_4.6
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:2.9.7-9.el8_4.6
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:2.9.7-13.el8_6.10
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service         unspecified  0:2.9.7-13.el8_6.10
  + 21 more
TIMELINE
  Jun 12  Reserved by redhat
  Jun 12  Published (CNA: redhat)
  Aug 31  EXPLOIT PUBLISHED — CVE-2025-6021 (libxml2). Public exploit reference added.
  Sep 1   EXPLOIT PUBLISHED — CVE-2025-6021 (libxml2). Public exploit reference added.
  Sep 18  EXPLOIT PUBLISHED — CVE-2025-6021 (libxml2). Public exploit reference added.
CWE-787 · CNA: redhat · CVSS v3.1 · 28 references · NVD status: Modified

Description

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.

Lifecycle

Complete event history — 5 events, chronological
DateEventDetail
June 12, 2025ReservedReserved by redhat
June 12, 2025PublishedPublished (CNA: redhat)
August 31, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2025-6021 (libxml2). Public exploit reference added.
September 1, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2025-6021 (libxml2). Public exploit reference added.
September 18, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2025-6021 (libxml2). Public exploit reference added.

Affected

Affected products and packages — 31 rows
VendorProduct / PackageEcosystemVersion introducedFixed
—libxml2———
Red HatRed Hat Enterprise Linux 10——0:2.12.5-7.el10_0
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support——0:2.9.1-6.el7_9.10
Red HatRed Hat Enterprise Linux 8——0:2.9.7-21.el8_10.1
Red HatRed Hat Enterprise Linux 8——0:2.9.7-21.el8_10.1
Red HatRed Hat Enterprise Linux 8.2 Advanced Update Support——0:2.9.7-9.el8_2.3
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support——0:2.9.7-9.el8_4.6
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On——0:2.9.7-9.el8_4.6
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support——0:2.9.7-13.el8_6.10
Red HatRed Hat Enterprise Linux 8.6 Telecommunications Update Service——0:2.9.7-13.el8_6.10
Red HatRed Hat Enterprise Linux 8.6 Update Services for SAP Solutions——0:2.9.7-13.el8_6.10
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service——0:2.9.7-16.el8_8.9
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions——0:2.9.7-16.el8_8.9
Red HatRed Hat Enterprise Linux 9——0:2.9.13-10.el9_6
Red HatRed Hat Enterprise Linux 9——0:2.9.13-10.el9_6
Red HatRed Hat Enterprise Linux 9.0 Update Services for SAP Solutions——0:2.9.13-1.el9_0.5
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions——0:2.9.13-3.el9_2.7
Red HatRed Hat Enterprise Linux 9.4 Extended Update Support——0:2.9.13-10.el9_4
Red HatRed Hat OpenShift Container Platform 4.12——412.86.202509030110-0
Red HatRed Hat OpenShift Container Platform 4.13——413.92.202509030117-0
Red HatRed Hat OpenShift Container Platform 4.14——414.92.202508041909-0
Red HatRed Hat OpenShift Container Platform 4.15——415.92.202508192014-0
Red HatRed Hat OpenShift Container Platform 4.16——416.94.202508050040-0
Red HatRed Hat OpenShift Container Platform 4.17——417.94.202508141510-0
Red HatRed Hat OpenShift Container Platform 4.18——418.94.202508060022-0
Red HatRed Hat OpenShift Container Platform 4.19——4.19.9.6.202507230107-0
Red HatRed Hat Discovery 2——2.0.1-1754478727
Red HatRed Hat Hardened Images——2.15.2-0.3.hum1
Red HatRed Hat Insights proxy 1.5——1.5.5-1754504343
Red HatRed Hat Enterprise Linux 6———
Red HatRed Hat OpenShift Container Platform 4———

Weaknesses

CWE-787

References (28)

Related

Authoritative record: CVE-2025-6021 at cve.org

Vendors: red hat

Weaknesses: CWE-787

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-6021 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.