VDB

RHSA-2025%3A14059

RHSA-2025%3A14059 PUBLISHED CVSS 7.5 HIGH

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatrhcos-ppc64le-417.94.202508141510-0 as a component of Red Hat OpenShift Container Platform 4.17rhcos-ppc64le-417.94.202508141510-0
Red Hatrhcos-x86_64-417.94.202508141510-0 as a component of Red Hat OpenShift Container Platform 4.17rhcos-x86_64-417.94.202508141510-0
Red Hatrhcos-s390x-417.94.202508141510-0 as a component of Red Hat OpenShift Container Platform 4.17rhcos-s390x-417.94.202508141510-0
Red Hatrhcos-aarch64-417.94.202508141510-0 as a component of Red Hat OpenShift Container Platform 4.17rhcos-aarch64-417.94.202508141510-0

Timeline

  • Aug 27, 2025 CVE Published
  • Apr 30, 2026 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›