CVE-2025-6170

Summary

A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.

Affected Software

VendorProductVersion RangeStatus
0 < 2.14.5affected
Red HatRed Hat Enterprise Linux 100:2.12.5-10.el10_2.2 < *unaffected
Red HatRed Hat Enterprise Linux 80:2.9.7-21.el8_10.6 < *unaffected
Red HatRed Hat Enterprise Linux 80:2.9.7-21.el8_10.6 < *unaffected
Red HatRed Hat Enterprise Linux 90:2.9.13-14.el9_8.2 < *unaffected
Red HatRed Hat Enterprise Linux 90:2.9.13-14.el9_8.2 < *unaffected
Red HatRed Hat Discovery 21784821670 < *unaffected
Red HatRed Hat Discovery 21784821750 < *unaffected
Red HatRed Hat Hardened Images2.15.2-0.3.hum1 < *unaffected
Red HatRed Hat Insights proxy 1.51786433656 < *unaffected
Red HatRed Hat Update Infrastructure 51784794818 < *unaffected
Red HatRed Hat Update Infrastructure 51784794778 < *unaffected
Red HatRed Hat Update Infrastructure 51784795112 < *unaffected
Red HatRed Hat Update Infrastructure 51784794289 < *unaffected
Red HatRed Hat Update Infrastructure 51784795076 < *unaffected

Weaknesses

  • CWE-121: Stack-based Buffer Overflow

Workarounds

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to a widespread installation base, or stability. It is strongly recommended to apply the upstream patch once available.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

CVE Program Container

Additional References

Additional References

References