Heap-Based Buffer Under-read in libxml2 Affects XML Validation
CVE-2025-32415
7.5HIGH
What is CVE-2025-32415?
A vulnerability in libxml2 prior to version 2.13.8 and 2.14.x before 2.14.2 allows for a heap-based buffer under-read. This can be exploited when a malicious XML document is validated against a specific XML schema requiring certain identity constraints or when a specially crafted XML schema is utilized. By triggering this vulnerability, attackers may gain unauthorized access to sensitive data or disrupt normal operations.
Affected Version(s)
libxml2 0 < 2.13.8
libxml2 2.14.0 < 2.14.2