[CLSA-2025:1760020147] Fix CVE(s): CVE-2025-9714
Type:
security
Severity:
Moderate
Release date:
2025-10-09 14:29:16 UTC
Description:
* SECURITY UPDATE: uncontrolled recursion causing stack overflow via crafted XPath expressions - debian/patches/CVE-2025-9714-*.patch: Add comprehensive XPath DoS protection including operation limits, recursion depth controls, and proper handling of recursive invocations to prevent stack overflows and resource exhaustion - CVE-2025-9714
Updated packages:
  • libxml2_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els13_amd64.deb
    sha:8a89fab163eebb0b1e768136bdb1c9287e7bbe83
  • libxml2-dev_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els13_amd64.deb
    sha:7d3b949ac4796bfa6be780ee24e5cb1917960249
  • libxml2-doc_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els13_all.deb
    sha:7087599efde27f5b9c1b53b6cf3163e7c9de544f
  • libxml2-utils_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els13_amd64.deb
    sha:b43aaba7e890042897ba81bc434642f1066c0374
  • python-libxml2_2.9.3+dfsg1-1ubuntu0.7+tuxcare.els13_amd64.deb
    sha:8fa20807d93b3ee52a4d9d0914a39015c54e043b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.