CVE-2025-6021
ADVISORY - nistSummary
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
Alpine
CREATED
UPDATED
ADVISORY IDCVE-2025-6021
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
| Package | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
|---|---|---|---|---|---|
| alpine/libxml2 | apk | alpine | 3.21 | <2.13.9-r0 | 2.13.9-r0 |
| alpine/libxml2 | apk | alpine | 3.23 | <2.13.9-r0 | 2.13.9-r0 |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.10.0-r0 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.10.3-r0 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.10.4-r0 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.12.10-r0 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.12.5-r0 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.12.7-r0 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.12.7-r1 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.12.7-r2 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.12.7-r3 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.9.10-r4 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.9.10-r5 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.9.11-r0 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.9.13-r0 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.9.14-r0 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.9.4-r1 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.9.4-r2 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.9.4-r4 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.9.8-r1 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.20 | <=2.9.8-r3 | Not yet available |
| alpine/libxml2 | apk | alpine | 3.24 | <2.13.9-r0 | 2.13.9-r0 |
| alpine/libxml2 | apk | alpine | edge | <2.13.9-r0 | 2.13.9-r0 |
| alpine/libxml2 | apk | alpine | 3.22 | <2.13.9-r0 | 2.13.9-r0 |
| alpine/qt6-qtwebengine | apk | alpine | edge | <0 | 0 |
| alpine/qt6-qtwebengine | apk | alpine | 3.23 | <0 | 0 |
| alpine/qt6-qtwebengine | apk | alpine | 3.24 | <0 | 0 |
| alpine/qt6-qtwebengine | apk | alpine | 3.22 | <6.8.3-r5 | 6.8.3-r5 |
Severity and metrics
No CVSS data available from this advisory.
NIST
CVSS SCORE
7.5highDebian
CREATED
UPDATED
ADVISORY IDCVE-2025-6021
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Ubuntu
CREATED
UPDATED
ADVISORY IDCVE-2025-6021
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumAlma
CREATED
UPDATED
ADVISORY IDALSA-2025:10698
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AhighAlma
CREATED
UPDATED
ADVISORY IDALSA-2025:10699
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AhighAmazon
CREATED
UPDATED
ADVISORY IDALAS2-2025-2893
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AhighAmazon
CREATED
UPDATED
ADVISORY IDALAS2023-2025-1019
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AhighRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2025-6021
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
7.5mediumRocky
CREATED
UPDATED
ADVISORY IDRLSA-2025:10630
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AhighRocky
CREATED
UPDATED
ADVISORY IDRLSA-2025:10698
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AhighRocky
CREATED
UPDATED
ADVISORY IDRLSA-2025:10699
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AhighOracle
CREATED
UPDATED
ADVISORY IDELSA-2025-10630
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AhighOracle
CREATED
UPDATED
ADVISORY IDELSA-2025-10698
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AhighOracle
CREATED
UPDATED
ADVISORY IDELSA-2025-10699
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AhighOracle
CREATED
UPDATED
ADVISORY IDELSA-2025-12240
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AhighPhoton
CREATED
UPDATED
ADVISORY ID
CVE-2025-6021
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-