CVE-2025-32415

Published Apr 17, 2025
·
Updated

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.

Affected Software

8 affected componentsFixes available
Gnome libxml2<2.13.8, >2.14.0<=2.14.2
Xmlsoft Libxml2<2.13.8
Xmlsoft Libxml2>=2.14.0<2.14.2
debian/libxml2<=2.9.10+dfsg-6.7+deb11u4, <=2.9.14+dfsg-1.3~deb12u1, <=2.12.7+dfsg+really2.9.14-0.4
2.9.10+dfsg-6.7+deb11u7
IBM DS8A00( R10.0 - R10.1 )<=10.1.3.0 - 10.10.106.0
IBM DS8900F ( R9.4)<=89.40.83.0-89.44.5.0
Microsoft azl3 libxml2 2.11.5-5
Microsoft cbl2 libxml2 2.10.4-7

Event History

Apr 17, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·06:01 PM
DescriptionSeverityAffected Software
May 2, 2025
Data Sourced
via Ubuntu·06:19 PM
RemedyDescriptionSeverityAffected Software
May 27, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Dec 18, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-32415?

CVE-2025-32415 is considered to have a medium severity due to heap-based buffer under-read vulnerabilities.

2

How do I fix CVE-2025-32415?

To fix CVE-2025-32415, upgrade to libxml2 version 2.13.8 or later, or 2.14.2 or later.

3

What software is affected by CVE-2025-32415?

CVE-2025-32415 affects libxml2 versions before 2.13.8 and 2.14.x before 2.14.2.

4

What types of attacks can CVE-2025-32415 lead to?

CVE-2025-32415 can potentially lead to denial of service or arbitrary code execution if exploited.

5

What are the implications of exploiting CVE-2025-32415?

Exploiting CVE-2025-32415 may allow attackers to manipulate data processed by vulnerable applications, leading to unexpected behavior.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203