CVE-2025-6021

ADVISORY - nist

Summary

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.

EPSS Score: 0.00638 (0.700)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Integer Overflow or Wraparound

Out-of-bounds Write

ADVISORY - redhat

Alpine

CREATED

UPDATED

ADVISORY IDCVE-2025-6021
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY
PackageTypeOS NameOS VersionAffected RangesFix Versions
alpine/libxml2apkalpine3.21<2.13.9-r02.13.9-r0
alpine/libxml2apkalpine3.23<2.13.9-r02.13.9-r0
alpine/libxml2apkalpine3.20<=2.10.0-r0Not yet available
alpine/libxml2apkalpine3.20<=2.10.3-r0Not yet available
alpine/libxml2apkalpine3.20<=2.10.4-r0Not yet available
alpine/libxml2apkalpine3.20<=2.12.10-r0Not yet available
alpine/libxml2apkalpine3.20<=2.12.5-r0Not yet available
alpine/libxml2apkalpine3.20<=2.12.7-r0Not yet available
alpine/libxml2apkalpine3.20<=2.12.7-r1Not yet available
alpine/libxml2apkalpine3.20<=2.12.7-r2Not yet available
alpine/libxml2apkalpine3.20<=2.12.7-r3Not yet available
alpine/libxml2apkalpine3.20<=2.9.10-r4Not yet available
alpine/libxml2apkalpine3.20<=2.9.10-r5Not yet available
alpine/libxml2apkalpine3.20<=2.9.11-r0Not yet available
alpine/libxml2apkalpine3.20<=2.9.13-r0Not yet available
alpine/libxml2apkalpine3.20<=2.9.14-r0Not yet available
alpine/libxml2apkalpine3.20<=2.9.4-r1Not yet available
alpine/libxml2apkalpine3.20<=2.9.4-r2Not yet available
alpine/libxml2apkalpine3.20<=2.9.4-r4Not yet available
alpine/libxml2apkalpine3.20<=2.9.8-r1Not yet available
alpine/libxml2apkalpine3.20<=2.9.8-r3Not yet available
alpine/libxml2apkalpine3.24<2.13.9-r02.13.9-r0
alpine/libxml2apkalpineedge<2.13.9-r02.13.9-r0
alpine/libxml2apkalpine3.22<2.13.9-r02.13.9-r0
alpine/qt6-qtwebengineapkalpineedge<00
alpine/qt6-qtwebengineapkalpine3.23<00
alpine/qt6-qtwebengineapkalpine3.24<00
alpine/qt6-qtwebengineapkalpine3.22<6.8.3-r56.8.3-r5

Severity and metrics

No CVSS data available from this advisory.

NIST

CREATED

UPDATED

ADVISORY IDCVE-2025-6021
EXPLOITABILITY SCORE

3.9

EXPLOITS FOUND
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

7.5high

Debian

CREATED

UPDATED

ADVISORY IDCVE-2025-6021
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

Ubuntu

CREATED

UPDATED

ADVISORY IDCVE-2025-6021
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium

Alma

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Ahigh

Alma

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Ahigh

Amazon

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Ahigh

Amazon

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Ahigh

Red Hat

CREATED

UPDATED

ADVISORY IDCVE-2025-6021
EXPLOITABILITY SCORE

3.9

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

7.5medium

Rocky

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Ahigh

Rocky

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Ahigh

Rocky

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Ahigh

Oracle

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Ahigh

Oracle

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Ahigh

Oracle

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Ahigh

Oracle

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Ahigh

Photon

CREATED

UPDATED

ADVISORY ID

CVE-2025-6021

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

7.5high