Description

Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled.

INFO

Published Date :

2025-09-10T18:43:12.204Z

Last Modified :

2025-11-03T18:14:19.914Z

Source :

canonical
AFFECTED PRODUCTS

The following products are affected by CVE-2025-9714 vulnerability.

Vendors Products
Gnome
  • Libxml2
Xmlsoft
  • Libxml2

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact