Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage
🔗 CVE IDs covered (10)
📋 Description
CVE-2024-12718 — cpython: python: Bypass extraction filter to modify file metadata outside extraction directory CVE-2025-4138 — cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory CVE-2025-4330 — cpython: python: Extraction filter bypass for linking outside extraction directory CVE-2025-4435 — cpython: Tarfile extracts filtered members when errorlevel=0 CVE-2025-4517 — python: cpython: Arbitrary writes via tarfile realpath overflow CVE-2025-6021 — libxml2: Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2 CVE-2025-6965 — sqlite: Integer Truncation in SQLite CVE-2025-7425 — libxslt: libxml2: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr CVE-2025-40909 — perl: Perl threads have a working directory race condition where file operations may target unintended paths CVE-2025-49796 — libxml: Type confusion leads to Denial of service (DoS)
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2025:13267
- externalhttps://access.redhat.com/security/cve/CVE-2024-12718
- externalhttps://access.redhat.com/security/cve/CVE-2025-40909
- externalhttps://access.redhat.com/security/cve/CVE-2025-4138
- externalhttps://access.redhat.com/security/cve/CVE-2025-4330
- externalhttps://access.redhat.com/security/cve/CVE-2025-4435
- externalhttps://access.redhat.com/security/cve/CVE-2025-4517
- externalhttps://access.redhat.com/security/cve/CVE-2025-49796
- externalhttps://access.redhat.com/security/cve/CVE-2025-6021
- externalhttps://access.redhat.com/security/cve/CVE-2025-6965
- externalhttps://access.redhat.com/security/cve/CVE-2025-7425
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/subscription_central/1-latest/#Discovery
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_13267.json