Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-6021

26
FAUCET Score

CVE-2025-6021 is a high-severity vulnerability in libxml2's xmlBuildQName function, affecting products from Red Hat and xmlsoft. It involves integer overflows during buffer size calculations, leading to a stack-based buffer overflow. This flaw can be exploited remotely with low complexity, potentially causing memory corruption or a denial of service. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.14.4CPE matchmatch criteria
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:redhat:jboss_core_services:-:*:*:*:*:*:*:*
4.12CPE matchmatch criteria
cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:*
4.13CPE matchmatch criteria
cpe:2.3:a:redhat:openshift_container_platform:4.13:*:*:*:*:*:*:*
4.14CPE matchmatch criteria
cpe:2.3:a:redhat:openshift_container_platform:4.14:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.12%
Probability of exploitation in next 30 days
EPSS Percentile
62.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0112 is in the 41st percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (35)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 19618-17084Fixed in: 2.11.5-6
microsoftpatch availablevia msrc
Product: 20212-17086Fixed in: 2.10.4-8
microsoftpatch availablevia msrc
Product: 19569-16823Fixed in: 2.10.4-8
microsoftpatch availablevia msrc
Product: cm2 libxml2 2.10.4-8 on CBL Mariner 2.0Fixed in: 2.10.4-8
microsoftpatch availablevia msrc
Product: cbl2 libxml2 2.10.4-8 on CBL Mariner 2.0Fixed in: 2.10.4-8
microsoftpatch availablevia msrc
Product: azl3 libxml2 2.11.5-6 on Azure Linux 3.0Fixed in: 2.11.5-6
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: libxml2-0:2.9.7-16.el8_8.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: libxml2-0:2.9.7-16.el8_8.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: libxml2-0:2.9.13-10.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: libxml2-0:2.9.13-1.el9_0.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: libxml2-0:2.9.13-3.el9_2.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: libxml2-0:2.9.13-10.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Core Services 2.4.62.SP2Fixed in: libxml2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.12Fixed in: rhcos-412.86.202509030110-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: libxml2-0:2.12.5-7.el10_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.14Fixed in: rhcos-414.92.202508041909-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: rhcos-415.92.202508192014-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.16Fixed in: rhcos-416.94.202508050040-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.17Fixed in: rhcos-417.94.202508141510-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.18Fixed in: rhcos-418.94.202508060022-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.19Fixed in: rhcos-4.19.9.6.202507230107-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-server-rhel9:sha256:c517869dacaf4d3650310d4a52e83706e0b311d6ebb4a9b37b1c7acff5c142ec
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Insights proxy 1.5Fixed in: insights-proxy/insights-proxy-container-rhel9:sha256:c26d589f12647890b67aaa986f54d3f7c6f7f2563fb5a73f38d559e6138739d7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.13Fixed in: rhcos-413.92.202509030117-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: libxml2-0:2.9.1-6.el7_9.10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: libxml2-0:2.9.7-21.el8_10.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: libxml2-0:2.9.7-9.el8_2.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: libxml2-0:2.9.7-9.el8_4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnFixed in: libxml2-0:2.9.7-9.el8_4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: libxml2-0:2.9.7-13.el8_6.10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: libxml2-0:2.9.7-13.el8_6.10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: libxml2-0:2.9.7-13.el8_6.10
View patch

Vendor Advisories (5)

honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
redhatCVE-2025-6021Moderate

libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2

Jun 12, 2025
microsoft2025-Jun/CVE-2025-6021Moderate

Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2

Jun 10, 2025

References

cert-portal.siemens.com / productcert/html/ssa-032379.html
lists.debian.org / debian-lts-announce/2025/07/msg00014.html
access.redhat.com / errata/RHSA-2025:10630
Third Party Advisory
access.redhat.com / errata/RHSA-2025:10698
Third Party Advisory
access.redhat.com / errata/RHSA-2025:10699
Third Party Advisory
access.redhat.com / errata/RHSA-2025:11580
Third Party Advisory
access.redhat.com / errata/RHSA-2025:11673
access.redhat.com / errata/RHSA-2025:12098
Third Party Advisory
access.redhat.com / errata/RHSA-2025:12099
Third Party Advisory
access.redhat.com / errata/RHSA-2025:12199
Third Party Advisory
access.redhat.com / errata/RHSA-2025:12237
Third Party Advisory
access.redhat.com / errata/RHSA-2025:12239
Third Party Advisory
access.redhat.com / errata/RHSA-2025:12240
Third Party Advisory
access.redhat.com / errata/RHSA-2025:12241
Third Party Advisory
access.redhat.com / errata/RHSA-2025:13267
Third Party Advisory
access.redhat.com / errata/RHSA-2025:13289
Third Party Advisory
access.redhat.com / errata/RHSA-2025:13325
Third Party Advisory
access.redhat.com / errata/RHSA-2025:13335
Third Party Advisory
access.redhat.com / errata/RHSA-2025:13336
Third Party Advisory
access.redhat.com / errata/RHSA-2025:14059
Third Party Advisory
access.redhat.com / errata/RHSA-2025:14396
Third Party Advisory
access.redhat.com / errata/RHSA-2025:15308
Third Party Advisory
access.redhat.com / errata/RHSA-2025:15672
Third Party Advisory
access.redhat.com / errata/RHSA-2025:19020
access.redhat.com / errata/RHSA-2026:7519
access.redhat.com / security/cve/CVE-2025-6021
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
gitlab.gnome.org / GNOME/libxml2/-/issues/926
ExploitIssue TrackingVendor Advisory