RHSA-2026:11349MediumCVSS 6.2

Red Hat Security Advisory: libxml2 security update

Published
April 28, 2026
Last Modified
August 26, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-9714 — libxslt: libxml2: Inifinite recursion at exsltDynMapFunction function in libexslt/dynamic.c

🎯 Affected products47

  • Red Hat Enterprise Linux AppStream (v. 8)
  • Red Hat Enterprise Linux BaseOS (v. 8)
  • libxml2-0:2.9.7-21.el8_10.4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • libxml2-0:2.9.7-21.el8_10.4.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • libxml2-0:2.9.7-21.el8_10.4.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • libxml2-0:2.9.7-21.el8_10.4.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • libxml2-0:2.9.7-21.el8_10.4.src as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • libxml2-0:2.9.7-21.el8_10.4.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • libxml2-debuginfo-0:2.9.7-21.el8_10.4.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libxml2-debuginfo-0:2.9.7-21.el8_10.4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • libxml2-debuginfo-0:2.9.7-21.el8_10.4.i686 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libxml2-debuginfo-0:2.9.7-21.el8_10.4.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • libxml2-debuginfo-0:2.9.7-21.el8_10.4.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libxml2-debuginfo-0:2.9.7-21.el8_10.4.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • libxml2-debuginfo-0:2.9.7-21.el8_10.4.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libxml2-debuginfo-0:2.9.7-21.el8_10.4.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • libxml2-debuginfo-0:2.9.7-21.el8_10.4.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libxml2-debuginfo-0:2.9.7-21.el8_10.4.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • libxml2-debugsource-0:2.9.7-21.el8_10.4.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libxml2-debugsource-0:2.9.7-21.el8_10.4.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • libxml2-debugsource-0:2.9.7-21.el8_10.4.i686 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libxml2-debugsource-0:2.9.7-21.el8_10.4.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • libxml2-debugsource-0:2.9.7-21.el8_10.4.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libxml2-debugsource-0:2.9.7-21.el8_10.4.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • libxml2-debugsource-0:2.9.7-21.el8_10.4.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libxml2-debugsource-0:2.9.7-21.el8_10.4.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • libxml2-debugsource-0:2.9.7-21.el8_10.4.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libxml2-debugsource-0:2.9.7-21.el8_10.4.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • libxml2-devel-0:2.9.7-21.el8_10.4.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libxml2-devel-0:2.9.7-21.el8_10.4.i686 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • +17 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: The impact of this flaw may be reduced by setting strict resource limits to the stack size of processes at the operational system level. This can be achieved either through the 'ulimit' shell built-in or the 'limits.conf' file.

🔗 References (4)