Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:10698 - Security Advisory
Issued:
2025-07-09
Updated:
2025-07-09

RHSA-2025:10698 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libxml2 security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libxml2 is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libxml2 library is a development toolbox providing the implementation of various XML standards.

Security Fix(es):

  • libxml: Heap use after free (UAF) leads to Denial of service (DoS) (CVE-2025-49794)
  • libxml: Type confusion leads to Denial of service (DoS) (CVE-2025-49796)
  • libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 (CVE-2025-6021)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 2372373 - CVE-2025-49794 libxml: Heap use after free (UAF) leads to Denial of service (DoS)
  • BZ - 2372385 - CVE-2025-49796 libxml: Type confusion leads to Denial of service (DoS)
  • BZ - 2372406 - CVE-2025-6021 libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2
  • RHEL-74345 - "oscap xccdf eval" fails with exit code 1 after printing "No bytes exported: xmlCode: -<randomvalue?>."

CVEs

  • CVE-2025-6021
  • CVE-2025-49794
  • CVE-2025-49796

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
libxml2-2.9.7-21.el8_10.1.src.rpm SHA-256: 589b44e6314c280f444ae03b00afe39a9bf130ce0051e4961f72ba4fb6f3ebff
x86_64
libxml2-2.9.7-21.el8_10.1.i686.rpm SHA-256: 9e71f59470ef27b4d30429d020aa1e05cbd82424a9eb8d3169c05db8533a3203
libxml2-2.9.7-21.el8_10.1.x86_64.rpm SHA-256: e2d8562201cf402c66c0c4f97d7f5eddff82dd413a7d62d1f686d90b5a2eb775
libxml2-debuginfo-2.9.7-21.el8_10.1.i686.rpm SHA-256: be6627f5fdaab05b00cb177bbbde4f041ed58ddab8990fc23957a09a69815fe7
libxml2-debuginfo-2.9.7-21.el8_10.1.i686.rpm SHA-256: be6627f5fdaab05b00cb177bbbde4f041ed58ddab8990fc23957a09a69815fe7
libxml2-debuginfo-2.9.7-21.el8_10.1.x86_64.rpm SHA-256: c97b715450c24a6855ccca5969bba5bb9c3c67fc786cfae3129000c1027fa2f0
libxml2-debuginfo-2.9.7-21.el8_10.1.x86_64.rpm SHA-256: c97b715450c24a6855ccca5969bba5bb9c3c67fc786cfae3129000c1027fa2f0
libxml2-debugsource-2.9.7-21.el8_10.1.i686.rpm SHA-256: 58779fe54656bc7cde6b36200b1e7869c302b0c96edfdaace0dad6bd10d5f23c
libxml2-debugsource-2.9.7-21.el8_10.1.i686.rpm SHA-256: 58779fe54656bc7cde6b36200b1e7869c302b0c96edfdaace0dad6bd10d5f23c
libxml2-debugsource-2.9.7-21.el8_10.1.x86_64.rpm SHA-256: 8fd683fb1391b7e305c0a0fb697823dfd9abf903ab76c5b2ead02b284073d6ab
libxml2-debugsource-2.9.7-21.el8_10.1.x86_64.rpm SHA-256: 8fd683fb1391b7e305c0a0fb697823dfd9abf903ab76c5b2ead02b284073d6ab
libxml2-devel-2.9.7-21.el8_10.1.i686.rpm SHA-256: b8477ac838e717329c6edca4f7860803fb8ca7b6b01b599906a277a5674eb008
libxml2-devel-2.9.7-21.el8_10.1.x86_64.rpm SHA-256: 0bafc39fc29b3c30b36d02cb0683ffa3f229e2b1a522bfd5770e7e68789745b5
python3-libxml2-2.9.7-21.el8_10.1.x86_64.rpm SHA-256: 44469ca50317ac689174969e2afc544b384abdd7edfd00af05a66d7e4de99d24
python3-libxml2-debuginfo-2.9.7-21.el8_10.1.i686.rpm SHA-256: db86f011f13edf8f4afdc7a637368b9ed80f6c47830c16e759b511860e963f82
python3-libxml2-debuginfo-2.9.7-21.el8_10.1.i686.rpm SHA-256: db86f011f13edf8f4afdc7a637368b9ed80f6c47830c16e759b511860e963f82
python3-libxml2-debuginfo-2.9.7-21.el8_10.1.x86_64.rpm SHA-256: ce8025b96c0dbde641ab880c203e9aa70c632aff778b4c87605a9cb99e5a455c
python3-libxml2-debuginfo-2.9.7-21.el8_10.1.x86_64.rpm SHA-256: ce8025b96c0dbde641ab880c203e9aa70c632aff778b4c87605a9cb99e5a455c

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
libxml2-2.9.7-21.el8_10.1.src.rpm SHA-256: 589b44e6314c280f444ae03b00afe39a9bf130ce0051e4961f72ba4fb6f3ebff
s390x
libxml2-2.9.7-21.el8_10.1.s390x.rpm SHA-256: c6feb921ff57b9c23717c03cc683c231067f879239cbe212eb2db1cd4685635f
libxml2-debuginfo-2.9.7-21.el8_10.1.s390x.rpm SHA-256: 829bc0b19e57b0e7f5c6fd471af7c0b0d706efd9ad3b3649ba0cc53032c65bfa
libxml2-debuginfo-2.9.7-21.el8_10.1.s390x.rpm SHA-256: 829bc0b19e57b0e7f5c6fd471af7c0b0d706efd9ad3b3649ba0cc53032c65bfa
libxml2-debugsource-2.9.7-21.el8_10.1.s390x.rpm SHA-256: f4d8c687802a9b9afc5bfd171141ac28c1121019de23b70600891c4460695495
libxml2-debugsource-2.9.7-21.el8_10.1.s390x.rpm SHA-256: f4d8c687802a9b9afc5bfd171141ac28c1121019de23b70600891c4460695495
libxml2-devel-2.9.7-21.el8_10.1.s390x.rpm SHA-256: 17de19f59d96bad8e009b03dab855eeb40aabe27ac4c2cc180679709e3adf5cb
python3-libxml2-2.9.7-21.el8_10.1.s390x.rpm SHA-256: ce6786770abc5413916b254a9e70f594623c0795918ba7ea47bf0a348adda3df
python3-libxml2-debuginfo-2.9.7-21.el8_10.1.s390x.rpm SHA-256: b3344f7159767fa794c12d1e9000dda73d32d8bc8918ca5cd8f267ec91b8df1e
python3-libxml2-debuginfo-2.9.7-21.el8_10.1.s390x.rpm SHA-256: b3344f7159767fa794c12d1e9000dda73d32d8bc8918ca5cd8f267ec91b8df1e

Red Hat Enterprise Linux for Power, little endian 8

SRPM
libxml2-2.9.7-21.el8_10.1.src.rpm SHA-256: 589b44e6314c280f444ae03b00afe39a9bf130ce0051e4961f72ba4fb6f3ebff
ppc64le
libxml2-2.9.7-21.el8_10.1.ppc64le.rpm SHA-256: 25281b04b9fa2c083f90337cd53861c427bbf8fbc18ed649421cda8a2f360392
libxml2-debuginfo-2.9.7-21.el8_10.1.ppc64le.rpm SHA-256: e2d1a58e6db4bd8abb2bfcf77d441a19a3b6dd7a45d0834ddc7c7deb43e299ac
libxml2-debuginfo-2.9.7-21.el8_10.1.ppc64le.rpm SHA-256: e2d1a58e6db4bd8abb2bfcf77d441a19a3b6dd7a45d0834ddc7c7deb43e299ac
libxml2-debugsource-2.9.7-21.el8_10.1.ppc64le.rpm SHA-256: a54ba980a90faa6ae007e874e1f258554616ed4587aec480ec540ca6ad74a3be
libxml2-debugsource-2.9.7-21.el8_10.1.ppc64le.rpm SHA-256: a54ba980a90faa6ae007e874e1f258554616ed4587aec480ec540ca6ad74a3be
libxml2-devel-2.9.7-21.el8_10.1.ppc64le.rpm SHA-256: a8962b07784bfded56b1b715f61737584173214445f34b07b6e1e26be640054c
python3-libxml2-2.9.7-21.el8_10.1.ppc64le.rpm SHA-256: eeed9c758552f13f87149d9de579a7aa757db3dab85fbfe153aef67520c74570
python3-libxml2-debuginfo-2.9.7-21.el8_10.1.ppc64le.rpm SHA-256: 5699d15edeeac3089bbe1683c3c09e9d603195aab4ea5fc414abf71a869dc149
python3-libxml2-debuginfo-2.9.7-21.el8_10.1.ppc64le.rpm SHA-256: 5699d15edeeac3089bbe1683c3c09e9d603195aab4ea5fc414abf71a869dc149

Red Hat Enterprise Linux for ARM 64 8

SRPM
libxml2-2.9.7-21.el8_10.1.src.rpm SHA-256: 589b44e6314c280f444ae03b00afe39a9bf130ce0051e4961f72ba4fb6f3ebff
aarch64
libxml2-2.9.7-21.el8_10.1.aarch64.rpm SHA-256: fe9b85220b382a4c6ab056bddb8ef2abe9b7ddb1b62081bfd3c662a87ae6a842
libxml2-debuginfo-2.9.7-21.el8_10.1.aarch64.rpm SHA-256: ba888caefe11f546f53d1a548b1198ece89b61df6544234d29c65842ba10d3ff
libxml2-debuginfo-2.9.7-21.el8_10.1.aarch64.rpm SHA-256: ba888caefe11f546f53d1a548b1198ece89b61df6544234d29c65842ba10d3ff
libxml2-debugsource-2.9.7-21.el8_10.1.aarch64.rpm SHA-256: c8f28b6010fff99c2a7c0941f8963319fe340e058f1ce882bcdec39ba8a96a77
libxml2-debugsource-2.9.7-21.el8_10.1.aarch64.rpm SHA-256: c8f28b6010fff99c2a7c0941f8963319fe340e058f1ce882bcdec39ba8a96a77
libxml2-devel-2.9.7-21.el8_10.1.aarch64.rpm SHA-256: 8a879d8c9cc0f9b7575d06bdc6cd966806a2b495fdc242bc7b28199b9eb5bb8e
python3-libxml2-2.9.7-21.el8_10.1.aarch64.rpm SHA-256: c2e1805da80d91a9144e5cc1ab4e0e34698324d7894c38d78b8e4c09123df541
python3-libxml2-debuginfo-2.9.7-21.el8_10.1.aarch64.rpm SHA-256: 75ada2d27ccfed9e6bd357411332e8eb1f6dfc6b75d0b38556e2859944f248d0
python3-libxml2-debuginfo-2.9.7-21.el8_10.1.aarch64.rpm SHA-256: 75ada2d27ccfed9e6bd357411332e8eb1f6dfc6b75d0b38556e2859944f248d0

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility