CVE-2024-25062

HIGH

libxml2 <2.11.7-2.12.5 - Use After Free

Title source: llm
STIX 2.1

Description

An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.

Scores

CVSS v3 7.5
EPSS 0.0138
EPSS Percentile 68.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-416
Status published
Products (1)
xmlsoft/libxml2 < 2.11.7
Published Feb 04, 2024
Tracked Since Feb 18, 2026