CRITICAL 9.1 Microsoft

CVE-2025-49796

Libxml: type confusion leads to denial of service (dos)

Microsoft Security Update 2025-Jun: Libxml: type confusion leads to denial of service (dos)

Affected Products

References

Published: 2025-06-10 · Source: Microsoft · Feed updated: 2026-08-15
This critical severity vulnerability with a CVSS score of 9.1 was published on 2025-06-10 via Microsoft. Affected: cm2 libxml2 2.10.4-8 on CBL Mariner 2.0, azl3 libxml2 2.11.5-6 on Azure Linux 3.0, cbl2 libxml2 2.10.4-8 on CBL Mariner 2.0 and 1 more.

Risk Timeline

CVE Disclosed2025-06-10 · 431 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2025-32463 PoCSudo before 1.9.17p1 allows local users to obtain root accessCRITICAL9.3
CVE-2025-49794Libxml: heap use after free (uaf) leads to denial of service (dos)CRITICAL9.1
CVE-2024-6174When a non-x86 platform is detected, cloud-init grants root access to a hardcodeHIGH8.8
CVE-2025-48387tar-fs has issue where extract can write outside the specified dir with a specifHIGH8.2
CVE-2025-0624Grub2: net: out-of-bounds write in grub_net_search_config_file()HIGH7.6
CVE-2025-47950CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream AmplificationHIGH7.5
vulnfeed aggregates 10939 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.