CRITICAL 9.1 Microsoft

CVE-2025-49796

Libxml: type confusion leads to denial of service (dos)

Microsoft Security Update 2025-Jun: Libxml: type confusion leads to denial of service (dos)

Affected Products

References

Published: 2025-06-10 · Source: Microsoft · Feed updated: 2026-09-30
This critical severity vulnerability with a CVSS score of 9.1 was published on 2025-06-10 via Microsoft. Affected: cm2 libxml2 2.10.4-8 on CBL Mariner 2.0, azl3 libxml2 2.11.5-6 on Azure Linux 3.0, cbl2 libxml2 2.10.4-8 on CBL Mariner 2.0 and 1 more.

Risk Timeline

CVE Disclosed2025-06-10 · 477 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2025-32463 PoCSudo before 1.9.17p1 allows local users to obtain root accessCRITICAL9.3
CVE-2025-49794Libxml: heap use after free (uaf) leads to denial of service (dos)CRITICAL9.1
CVE-2024-6174When a non-x86 platform is detected, cloud-init grants root access to a hardcodeHIGH8.8
CVE-2025-53547Helm Chart Dependency Updating With Malicious Chart.yaml Content And Symlink CanHIGH8.6
CVE-2025-48387tar-fs has issue where extract can write outside the specified dir with a specifHIGH8.2
CVE-2025-0624Grub2: net: out-of-bounds write in grub_net_search_config_file()HIGH7.6
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.