A vulnerability was found in libxml2. (CVE-2025-49796)
A critical vulnerability (CVE-2025-49796) in the libxml2 library involves a type confusion issue triggered by processing certain sch:name elements in XML input. This flaw can cause memory corruption leading to denial of service or other undefined behaviors due to corrupted memory. The vulnerability has a CVSS score of 9.1, indicating high severity. Red Hat has issued security advisories and patches addressing this and related libxml2 vulnerabilities. Updated packages are available for Red Hat Enterprise Linux 10 and related variants. No known exploits in the wild have been reported at this time.
AI Analysis
Technical Summary
CVE-2025-49796 is a critical vulnerability in libxml2 caused by type confusion when processing specific sch:name elements in XML files. This leads to memory corruption, potentially causing the libxml2 library to crash or exhibit undefined behavior due to corrupted memory. The vulnerability is classified under CWE-125 (Out-of-bounds Read). Red Hat has released multiple security advisories with patches for affected versions, primarily targeting Red Hat Enterprise Linux 10 and its extended update support versions. The CVSS v3.1 base score is 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H), indicating network exploitable with no privileges or user interaction required, causing high impact on integrity and availability. No public exploits are currently known.
Potential Impact
Successful exploitation can cause denial of service by crashing libxml2 or lead to undefined behavior due to memory corruption, potentially affecting the integrity and availability of applications relying on libxml2 for XML processing. There is no confirmed confidentiality impact. The vulnerability is remotely exploitable without authentication or user interaction.
Mitigation Recommendations
Red Hat has released official security updates addressing CVE-2025-49796 and related libxml2 vulnerabilities. Users of Red Hat Enterprise Linux 10 and related distributions should apply the provided patches promptly. Refer to Red Hat advisories RHSA-2025:10630 and others for detailed update instructions. No additional mitigation steps are required beyond applying the official patches.
A vulnerability was found in libxml2. (CVE-2025-49796)
Description
A critical vulnerability (CVE-2025-49796) in the libxml2 library involves a type confusion issue triggered by processing certain sch:name elements in XML input. This flaw can cause memory corruption leading to denial of service or other undefined behaviors due to corrupted memory. The vulnerability has a CVSS score of 9.1, indicating high severity. Red Hat has issued security advisories and patches addressing this and related libxml2 vulnerabilities. Updated packages are available for Red Hat Enterprise Linux 10 and related variants. No known exploits in the wild have been reported at this time.
CVSS v3.1
Score 9.1critical
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-49796 is a critical vulnerability in libxml2 caused by type confusion when processing specific sch:name elements in XML files. This leads to memory corruption, potentially causing the libxml2 library to crash or exhibit undefined behavior due to corrupted memory. The vulnerability is classified under CWE-125 (Out-of-bounds Read). Red Hat has released multiple security advisories with patches for affected versions, primarily targeting Red Hat Enterprise Linux 10 and its extended update support versions. The CVSS v3.1 base score is 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H), indicating network exploitable with no privileges or user interaction required, causing high impact on integrity and availability. No public exploits are currently known.
Potential Impact
Successful exploitation can cause denial of service by crashing libxml2 or lead to undefined behavior due to memory corruption, potentially affecting the integrity and availability of applications relying on libxml2 for XML processing. There is no confirmed confidentiality impact. The vulnerability is remotely exploitable without authentication or user interaction.
Mitigation Recommendations
Red Hat has released official security updates addressing CVE-2025-49796 and related libxml2 vulnerabilities. Users of Red Hat Enterprise Linux 10 and related distributions should apply the provided patches promptly. Refer to Red Hat advisories RHSA-2025:10630 and others for detailed update instructions. No additional mitigation steps are required beyond applying the official patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-83xx-9f6p-vwfj
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-49796"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Patch Information
- https://access.redhat.com/errata/RHSA-2025:10630
- https://access.redhat.com/errata/RHSA-2025:18219
- https://access.redhat.com/errata/RHSA-2025:18240
- https://access.redhat.com/errata/RHSA-2025:19020
- https://access.redhat.com/errata/RHSA-2025:19041
- https://access.redhat.com/errata/RHSA-2025:19046
- https://access.redhat.com/errata/RHSA-2025:19894
- https://access.redhat.com/errata/RHSA-2025:21913
- https://access.redhat.com/errata/RHSA-2026:0934
- https://access.redhat.com/errata/RHSA-2026:62549
- https://access.redhat.com/errata/RHSA-2026:7519
- https://access.redhat.com/errata/RHSA-2025:10698
Threat ID: 6aa2af50acd9273b4925a03b
Added to database: 09/10/2026, 13:23:28 UTC
Last enriched: 09/10/2026, 13:25:32 UTC
Last updated: 09/10/2026, 19:24:56 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.