CVE-2025-49794 Details
Description
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.
A use-after-free vulnerability has been identified in libxml2, specifically within the Schematron processing of XPath elements. This issue arises in the 'xmlSchematronGetNode' function when handling 'sch:name' schema elements. The vulnerability allows a malicious actor to craft an XML document that, when parsed by libxml2, can lead to a program crash or other undefined behaviors.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 16, 2025CISA-ADP
Assessed Jun 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-825 | Expired Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| libxml2 | All versions |
CPE
Remediation
| |
Change History
50 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 18, 2026 | CVE Modified | [email protected] |
| Sep 10, 2026 | CVE Modified | [email protected] |
| Sep 6, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | siemens-SADP |
| Aug 31, 2026 | CVE Modified | CVE |
| Aug 24, 2026 | CVE Modified | [email protected] |
| Aug 23, 2026 | CVE Modified | [email protected] |
| Aug 21, 2026 | CVE Modified | [email protected] |
| Aug 17, 2026 | CVE Modified | [email protected] |
| Aug 16, 2026 | CVE Modified | [email protected] |
| Aug 16, 2026 | CVE Modified | [email protected] |
| Aug 12, 2026 | CVE Modified | [email protected] |
| Aug 8, 2026 | CVE Modified | [email protected] |
| Aug 2, 2026 | CVE Modified | [email protected] |
| Jul 19, 2026 | CVE Modified | [email protected] |
| Jun 29, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | siemens-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 2, 2026 | CVE Modified | siemens-SADP |
| May 12, 2026 | CVE Modified | siemens-SADP |
| Apr 19, 2026 | CVE Modified | [email protected] |
| Mar 20, 2026 | CVE Modified | [email protected] |
| Jan 22, 2026 | CVE Modified | [email protected] |
| Nov 22, 2025 | CVE Modified | [email protected] |
| Nov 13, 2025 | CVE Modified | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Oct 30, 2025 | CVE Modified | [email protected] |
| Oct 29, 2025 | CVE Modified | [email protected] |
| Oct 27, 2025 | CVE Modified | [email protected] |
| Oct 24, 2025 | CVE Modified | [email protected] |
| Oct 22, 2025 | CVE Modified | [email protected] |
| Oct 22, 2025 | CVE Modified | [email protected] |
| Oct 21, 2025 | CVE Modified | [email protected] |
| Oct 16, 2025 | CVE Modified | [email protected] |
| Sep 15, 2025 | CVE Modified | [email protected] |
| Sep 15, 2025 | CVE Modified | [email protected] |
| Aug 7, 2025 | CVE Modified | [email protected] |
| Jul 30, 2025 | CVE Modified | [email protected] |
| Jul 30, 2025 | CVE Modified | [email protected] |
| Jul 29, 2025 | CVE Modified | [email protected] |
| Jul 29, 2025 | CVE Modified | [email protected] |
| Jul 29, 2025 | CVE Modified | [email protected] |
| Jul 23, 2025 | CVE Modified | [email protected] |
| Jul 9, 2025 | CVE Modified | [email protected] |
| Jul 9, 2025 | CVE Modified | [email protected] |
| Jun 16, 2025 | New CVE Received | [email protected] |
Volerion