RHSA-2025:13267HighCVSS 9.1

Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage

Published
August 6, 2025
Last Modified
June 3, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2024-12718 — cpython: python: Bypass extraction filter to modify file metadata outside extraction directory CVE-2025-4138 — cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory CVE-2025-4330 — cpython: python: Extraction filter bypass for linking outside extraction directory CVE-2025-4435 — cpython: Tarfile extracts filtered members when errorlevel=0 CVE-2025-4517 — python: cpython: Arbitrary writes via tarfile realpath overflow CVE-2025-6021 — libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 CVE-2025-6965 — sqlite: Integer Truncation in SQLite CVE-2025-7425 — libxslt: libxml2: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr CVE-2025-40909 — perl: Perl threads have a working directory race condition where file operations may target unintended paths CVE-2025-49796 — libxml: Type confusion leads to Denial of service (DoS)

🔗 References (14)