CVE-2025-6021: Out-of-bounds Write
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
AI Analysis
Technical Summary
The vulnerability CVE-2025-6021 exists in libxml2's xmlBuildQName function due to integer overflow in buffer size calculations, resulting in a stack-based buffer overflow. This can cause memory corruption or denial of service. The issue affects Red Hat Enterprise Linux versions 8 (>=8.0.0 <8.10.1) and 10 (>=10.0.0 <10.2.5). Red Hat has issued security advisories RHSA-2025:10630 and RHSA-2025:10698 providing patches that fix this vulnerability along with other related libxml2 issues. The CVSS v3.1 base score is 7.5 (high severity) with network attack vector, low attack complexity, no privileges or user interaction required, and an impact limited to availability (denial of service).
Potential Impact
Successful exploitation of this vulnerability can cause a denial of service due to a stack-based buffer overflow triggered by integer overflow in libxml2's xmlBuildQName function. There is no confirmed impact on confidentiality or integrity. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Red Hat has released official security updates for libxml2 that address CVE-2025-6021. Users should apply the updates as described in Red Hat advisories RHSA-2025:10630 and RHSA-2025:10698. The advisories provide detailed instructions for updating affected Red Hat Enterprise Linux 8 and 10 systems. Applying these patches mitigates the vulnerability. No additional mitigation steps are indicated by the vendor.
CVE-2025-6021: Out-of-bounds Write
Description
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
CVSS v3.1
Score 7.5high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2025-6021 exists in libxml2's xmlBuildQName function due to integer overflow in buffer size calculations, resulting in a stack-based buffer overflow. This can cause memory corruption or denial of service. The issue affects Red Hat Enterprise Linux versions 8 (>=8.0.0 <8.10.1) and 10 (>=10.0.0 <10.2.5). Red Hat has issued security advisories RHSA-2025:10630 and RHSA-2025:10698 providing patches that fix this vulnerability along with other related libxml2 issues. The CVSS v3.1 base score is 7.5 (high severity) with network attack vector, low attack complexity, no privileges or user interaction required, and an impact limited to availability (denial of service).
Potential Impact
Successful exploitation of this vulnerability can cause a denial of service due to a stack-based buffer overflow triggered by integer overflow in libxml2's xmlBuildQName function. There is no confirmed impact on confidentiality or integrity. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Red Hat has released official security updates for libxml2 that address CVE-2025-6021. Users should apply the updates as described in Red Hat advisories RHSA-2025:10630 and RHSA-2025:10698. The advisories provide detailed instructions for updating affected Red Hat Enterprise Linux 8 and 10 systems. Applying these patches mitigates the vulnerability. No additional mitigation steps are indicated by the vendor.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- redhat
- Date Reserved
- 2025-06-12T05:52:54.211Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/errata/RHSA-2025:10630","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10698","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:10699","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:11580","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:11673","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:12098","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:12099","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:12199","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:12237","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:12239","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:12240","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:12241","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:13267","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:13289","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:13325","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:13335","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:13336","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:14059","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:14396","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:15308","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:15672","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:19020","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:7519","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2025-6021","vendor":"Red Hat"}]
Threat ID: 684ad14d358c65714e6a717c
Added to database: 06/12/2025, 13:08:29 UTC
Last enriched: 07/02/2026, 21:58:48 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 259
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.