GHSA-32vr-5hxf-x93f · Severity: high — A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size...
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
Conclusion & alert: CVE-2025-6021 is rated High Exploit Risk (65/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.07%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 2.12% | 1.07% | -1.05% |
| 2 | 2026-04-22 | 1.73% | 2.12% | +0.38% |
| 3 | 2026-04-21 | — | 1.73% | — |
Full EPSS history (33 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-32vr-5hxf-x93f · Severity: high — A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size...
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2025-6021: 2 source package rows (libxml2, qt6-qtwebengine); 129 state rows across 8 repos (3.19-main, 3.20-main, 3.21-main, 3.22-community, 3.22-main, 3.23-main, edge-community, edge-main); fixed 7, open 122. | https://security.alpinelinux.org/vuln/CVE-2025-6021 |
debian
|
not yet assigned | CVE-2025-6021 not yet assigned priority: Debian including 1 source packages (libxml2), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2025-6021 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2025-6021 |
suse
|
high | CVE-2025-6021 severity important: SUSE including 364 source package names (0.23.1-11.20:libxml2-2-2.10.3-150500.5.29.1, 0.3.2-1.2:libxml2-2-2.10.3-150500.5.29.1, …), 1223 product×package rows across 385 product lines (Container bci/kiwi, Container bci/spack, … (385 product lines)): Fixed 769, Known Not Affected 233, Known Affected 221. | https://www.suse.com/security/cve/CVE-2025-6021/ |
ubuntu
|
medium | CVE-2025-6021 medium priority: Ubuntu including 1 source packages (libxml2), 9 status rows across 9 suites (bionic, focal, jammy, noble, oracular, plucky, trusty, upstream, xenial): released 8, ignored 1. | https://ubuntu.com/security/CVE-2025-6021 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| xmlsoft | libxml2 | < 2.14.4 | cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* |
| redhat | jboss_core_services | — | cpe:2.3:a:redhat:jboss_core_services:-:*:*:*:*:*:*:* |
| redhat | openshift_container_platform | 4.12 | cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:* |
| redhat | openshift_container_platform | 4.13 | cpe:2.3:a:redhat:openshift_container_platform:4.13:*:*:*:*:*:*:* |
| redhat | openshift_container_platform | 4.14 | cpe:2.3:a:redhat:openshift_container_platform:4.14:*:*:*:*:*:*:* |
| redhat | openshift_container_platform | 4.15 | cpe:2.3:a:redhat:openshift_container_platform:4.15:*:*:*:*:*:*:* |
| redhat | openshift_container_platform | 4.16 | cpe:2.3:a:redhat:openshift_container_platform:4.16:*:*:*:*:*:*:* |
| redhat | openshift_container_platform | 4.17 | cpe:2.3:a:redhat:openshift_container_platform:4.17:*:*:*:*:*:*:* |
| redhat | openshift_container_platform | 4.18 | cpe:2.3:a:redhat:openshift_container_platform:4.18:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_arm64 | 4.13 | cpe:2.3:a:redhat:openshift_container_platform_for_arm64:4.13:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_arm64 | 4.14 | cpe:2.3:a:redhat:openshift_container_platform_for_arm64:4.14:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_arm64 | 4.15 | cpe:2.3:a:redhat:openshift_container_platform_for_arm64:4.15:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_arm64 | 4.16 | cpe:2.3:a:redhat:openshift_container_platform_for_arm64:4.16:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_arm64 | 4.17 | cpe:2.3:a:redhat:openshift_container_platform_for_arm64:4.17:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_arm64 | 4.18 | cpe:2.3:a:redhat:openshift_container_platform_for_arm64:4.18:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_ibm_z | 4.13 | cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.13:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_ibm_z | 4.14 | cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.14:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_ibm_z | 4.15 | cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.15:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_ibm_z | 4.16 | cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.16:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_ibm_z | 4.17 | cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.17:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_ibm_z | 4.18 | cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.18:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_linuxone | 4.13 | cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.13:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_linuxone | 4.14 | cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.14:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_linuxone | 4.15 | cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.15:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_linuxone | 4.16 | cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.16:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_linuxone | 4.17 | cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.17:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_linuxone | 4.18 | cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.18:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_power | 4.13 | cpe:2.3:a:redhat:openshift_container_platform_for_power:4.13:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_power | 4.14 | cpe:2.3:a:redhat:openshift_container_platform_for_power:4.14:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_power | 4.15 | cpe:2.3:a:redhat:openshift_container_platform_for_power:4.15:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_power | 4.16 | cpe:2.3:a:redhat:openshift_container_platform_for_power:4.16:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_power | 4.17 | cpe:2.3:a:redhat:openshift_container_platform_for_power:4.17:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_power | 4.18 | cpe:2.3:a:redhat:openshift_container_platform_for_power:4.18:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 8.0 | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 9.0 | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 10.0 | cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_eus | 8.4 | cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:* |
| redhat | enterprise_linux_eus | 8.6 | cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:* |
| redhat | enterprise_linux_eus | 8.8 | cpe:2.3:o:redhat:enterprise_linux_eus:8.8:*:*:*:*:*:*:* |
| redhat | enterprise_linux_eus | 9.4 | cpe:2.3:o:redhat:enterprise_linux_eus:9.4:*:*:*:*:*:*:* |
| redhat | enterprise_linux_eus | 9.6 | cpe:2.3:o:redhat:enterprise_linux_eus:9.6:*:*:*:*:*:*:* |
| redhat | enterprise_linux_eus | 10.0 | cpe:2.3:o:redhat:enterprise_linux_eus:10.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_arm_64 | 8.0_aarch64 | cpe:2.3:o:redhat:enterprise_linux_for_arm_64:8.0_aarch64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_arm_64 | 9.0_aarch64 | cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.0_aarch64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_arm_64 | 9.4_aarch64 | cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.4_aarch64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_arm_64 | 10.0_aarch64 | cpe:2.3:o:redhat:enterprise_linux_for_arm_64:10.0_aarch64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_arm_64_eus | 9.4_aarch64 | cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:9.4_aarch64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_arm_64_eus | 9.6_aarch64 | cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:9.6_aarch64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_arm_64_eus | 10.0_aarch64 | cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:10.0_aarch64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems | 8.0_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems | 9.4_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.4_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems | 10.0_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:10.0_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 9.0_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:9.0_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 9.4_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:9.4_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 9.6_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:9.6_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 10.0_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:10.0_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian | 8.0_ppc64le | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0_ppc64le:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian | 9.0_ppc64le | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:9.0_ppc64le:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian | 10.0_ppc64le | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:10.0_ppc64le:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian_eus | 9.4_ppc64le | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:9.4_ppc64le:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian_eus | 9.6_ppc64le | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:9.6_ppc64le:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian_eus | 10.0_ppc64le | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:10.0_ppc64le:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server | 7.0 | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_aus | 8.2 | cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_aus | 8.4 | cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_aus | 8.6 | cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_aus | 9.2 | cpe:2.3:o:redhat:enterprise_linux_server_aus:9.2:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_aus | 9.4 | cpe:2.3:o:redhat:enterprise_linux_server_aus:9.4:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_aus | 9.6 | cpe:2.3:o:redhat:enterprise_linux_server_aus:9.6:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 9.4_ppc64le | cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:9.4_ppc64le:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_tus | 8.8 | cpe:2.3:o:redhat:enterprise_linux_server_tus:8.8:*:*:*:*:*:*:* |
| redhat | in-vehicle_operating_system | 1.0 | cpe:2.3:o:redhat:in-vehicle_operating_system:1.0:*:*:*:*:*:*:* |