CVE-2025-9714
MEDIUMlibxml2 <= 2.9.14 - Uncontrolled Recursion in XPath Evaluation
Title source: llmDescription
Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled.
References (3)
Core 3
Core References
Patch patch
https://gitlab.gnome.org/GNOME/libxml2/-/commit/677a42645ef22b5a50741bad5facf9d8a8bc6d21
Vendor Advisory
https://cert-portal.siemens.com/productcert/html/ssa-577017.html
Scores
CVSS v3
6.2
EPSS
0.0014
EPSS Percentile
4.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-674
Status
published
Products (9)
libxml2/libxml2
< 2.10.0
libxml2/libxml2
< 2.12.7+dfsg+really2.9.14-0.4ubuntu0.3
libxml2/libxml2
< 2.9.1+dfsg1-3ubuntu4.13+esm9
libxml2/libxml2
< 2.9.10+dfsg-5ubuntu0.20.04.10+esm2
libxml2/libxml2
< 2.9.13+dfsg-1ubuntu0.9
libxml2/libxml2
< 2.9.14+dfsg-1.3ubuntu3.5
libxml2/libxml2
< 2.9.3+dfsg1-1ubuntu0.7+esm10
libxml2/libxml2
< 2.9.4+dfsg1-6.1ubuntu1.9+esm5
xmlsoft/libxml2
< 2.10.0
Published
Sep 10, 2025
Tracked Since
Feb 18, 2026