CVE-2025-8732

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."
References
Link Resource
https://drive.google.com/file/d/1woIeYVcSQB_NwfEhaVnX6MedpWJ_nqWl/view?usp=drive_link Broken Link
https://gitlab.gnome.org/GNOME/libxml2/-/issues/958 Exploit Issue Tracking Third Party Advisory
https://gitlab.gnome.org/GNOME/libxml2/-/issues/958#note_2505853 Exploit Issue Tracking Third Party Advisory
https://vuldb.com/?ctiid.319228 Permissions Required Third Party Advisory
https://vuldb.com/?id.319228 Permissions Required Third Party Advisory
https://vuldb.com/?submit.622285 Permissions Required Third Party Advisory
https://cert-portal.siemens.com/productcert/html/ssa-253495.html Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:ruggedcom_rst2428p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ruggedcom_rst2428p:-:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:vios:4.1.2.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:7.3.4:*:*:*:*:*:*:*

History

01 Jul 2026, 15:25

Type Values Removed Values Added
CPE cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:7.3.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:vios:4.1.2.0:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ruggedcom_rst2428p:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:ruggedcom_rst2428p_firmware:*:*:*:*:*:*:*:*
First Time Siemens
Ibm aix
Xmlsoft libxml2
Siemens ruggedcom Rst2428p
Siemens ruggedcom Rst2428p Firmware
Ibm
Xmlsoft
Ibm vios
References () https://drive.google.com/file/d/1woIeYVcSQB_NwfEhaVnX6MedpWJ_nqWl/view?usp=drive_link - () https://drive.google.com/file/d/1woIeYVcSQB_NwfEhaVnX6MedpWJ_nqWl/view?usp=drive_link - Broken Link
References () https://gitlab.gnome.org/GNOME/libxml2/-/issues/958 - () https://gitlab.gnome.org/GNOME/libxml2/-/issues/958 - Exploit, Issue Tracking, Third Party Advisory
References () https://gitlab.gnome.org/GNOME/libxml2/-/issues/958#note_2505853 - () https://gitlab.gnome.org/GNOME/libxml2/-/issues/958#note_2505853 - Exploit, Issue Tracking, Third Party Advisory
References () https://vuldb.com/?ctiid.319228 - () https://vuldb.com/?ctiid.319228 - Permissions Required, Third Party Advisory
References () https://vuldb.com/?id.319228 - () https://vuldb.com/?id.319228 - Permissions Required, Third Party Advisory
References () https://vuldb.com/?submit.622285 - () https://vuldb.com/?submit.622285 - Permissions Required, Third Party Advisory
References () https://cert-portal.siemens.com/productcert/html/ssa-253495.html - () https://cert-portal.siemens.com/productcert/html/ssa-253495.html - Third Party Advisory

02 Jun 2026, 14:16

Type Values Removed Values Added
References
  • () https://cert-portal.siemens.com/productcert/html/ssa-253495.html -

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en libxml2 hasta la versión 2.14.5. Se ha declarado problemática. Esta vulnerabilidad afecta a la función xmlParseSGMLCatalog del componente xmlcatalog. La manipulación provoca recursión incontrolada. Es necesario atacar localmente. Se ha hecho público el exploit y puede que sea utilizado. La existencia real de esta vulnerabilidad aún se duda. El responsable del código explica que «el problema solo puede desencadenarse con catálogos SGML no confiables y no tiene ningún sentido usarlos. Dudo también que alguien siga utilizando catálogos SGML».

08 Aug 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-08 17:15

Updated : 2026-07-01 15:25


NVD link : CVE-2025-8732

Mitre link : CVE-2025-8732

CVE.ORG link : CVE-2025-8732


JSON object : View

Products Affected

ibm

  • aix
  • vios

siemens

  • ruggedcom_rst2428p
  • ruggedcom_rst2428p_firmware

xmlsoft

  • libxml2
CWE
CWE-404

Improper Resource Shutdown or Release

CWE-674

Uncontrolled Recursion