suse · CVE-2025-6491

Quick triage

Priority: medium Published: 2025-07-12 06:55:27 UTC Updated: 2026-03-05 01:29:51 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2025-6491 severity moderate: SUSE including 351 source package names (apache2-mod_php7-7.4.33-150400.4.51.1, apache2-mod_php8-8.0.30-150400.4.57.1, …), 1291 product×package rows across 20 product lines (SUSE Liberty Linux 8, SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS, … (20 product lines)): Fixed 1291.

Description:

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and affect the availability of the target server.

cvelogic Threat Intelligence