Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian: libxml2 Critical Memory Corruption Fix CVE-2025-7425 DSA-5990-1

debian
Calendar Grey August 29, 2025
Debian Logo
A significant vulnerability notice concerning libxml2 highlights a flaw in memory handling that demands prompt attention from all users.
A flaw was found in libxslt, the XSLT 1.0 processing library, where the attribute type, atype, flags are modified in a way that corrupts internal memory management

Summary

For the oldstable distribution (bookworm), this problem has been fixed
in version 2.9.14+dfsg-1.3~deb12u4.

For the stable distribution (trixie), this problem has been fixed in
version 2.12.7+dfsg+really2.9.14-2.1+deb13u1.

We recommend that you upgrade your libxml2 packages.

For the detailed security status of libxml2 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libxml2

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: libxml2
CVE ID: CVE-2025-7425

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here