Buffer Overflow Vulnerability in xmllint Command-Line Tool by Red Hat
CVE-2025-6170

2.5LOW

What is CVE-2025-6170?

A flaw has been identified in the xmllint command-line tool, which is integral for parsing XML files. This vulnerability arises from improper input size checks when users provide excessively long commands. Such a lack of validation can lead to crashes and may potentially allow attackers to execute unauthorized code under specific configurations lacking modern security defenses.

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Ahmed Lekssays for reporting this issue.
.
CVE-2025-6170 : Buffer Overflow Vulnerability in xmllint Command-Line Tool by Red Hat