CVE-2025-49796: Libxml: type confusion leads to denial of service (dos)
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49796?
The severity of CVE-2025-49796 is classified as high due to its potential to cause denial of service.
How do I fix CVE-2025-49796?
To fix CVE-2025-49796, update to the latest version of libxml2 where the vulnerability is addressed.
What types of attacks can CVE-2025-49796 facilitate?
CVE-2025-49796 can facilitate denial of service attacks by crashing applications that rely on libxml2.
Which software is affected by CVE-2025-49796?
CVE-2025-49796 affects the GNOME libxml2 library.
What are the implications of CVE-2025-49796 for users?
The implications of CVE-2025-49796 for users include possible disruptions due to application crashes when processing malicious XML files.