Buffer Overflow Vulnerability in xmllint Command-Line Tool by Red Hat
CVE-2025-6170

2.5LOW

Key Information:

Badges

👾 Exploit Exists📰 News Worthy

What is CVE-2025-6170?

A flaw has been identified in the xmllint command-line tool, which is integral for parsing XML files. This vulnerability arises from improper input size checks when users provide excessively long commands. Such a lack of validation can lead to crashes and may potentially allow attackers to execute unauthorized code under specific configurations lacking modern security defenses.

News Articles

Former US Army Sergeant admits he sold secrets to China

Infosec in brief A former US Army sergeant has admitted he attempted to sell classified data to China. Joseph Daniel Schmidt last Friday pled guilty after the Feds charged him with using his top secret...

3 weeks ago

Former US Army Sergeant pleads guilty after amateurish attempt at selling secrets to China

Infosec in brief A former US Army sergeant has admitted he attempted to sell classified data to China. Joseph Daniel Schmidt last Friday pled guilty after the Feds charged him with using his top secret...

3 weeks ago

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by The Register

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Ahmed Lekssays for reporting this issue.
.
CVE-2025-6170 : Buffer Overflow Vulnerability in xmllint Command-Line Tool by Red Hat