---
id: CVE-2025-6170
title: >-
  A flaw was found in the interactive shell of the xmllint command-line tool,
  used for parsing XML files
summary: >-
  A flaw was found in the interactive shell of the xmllint command-line tool,
  used for parsing XML files. When a user inputs an overly long command, the
  program does not check the input size properly, which can cause it to crash.
  This issu…
severity: low
cvss: 2.5
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L'
cwe:
  - CWE-121
vendor: redhat
product: jboss_core_services
affected:
  - jboss_core_services
  - openshift_container_platform = 4.0
  - enterprise_linux = 6.0
  - enterprise_linux = 7.0
  - enterprise_linux = 8.0
  - enterprise_linux = 9.0
  - enterprise_linux = 10.0
  - libxml2
published: '2025-06-16'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T12:17:04.023'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-6170'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:36734'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:39304'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:39317'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:44481'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:46836'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:53371'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:58981'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:70596'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:70639'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:7519'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-6170'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2372952'
    label: secalert@redhat.com
  - url: 'https://gitlab.gnome.org/GNOME/libxml2/-/issues/941'
    label: secalert@redhat.com
  - url: 'https://lists.debian.org/debian-lts-announce/2025/07/msg00014.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-253495.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6170.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-6170'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-6170'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2025-06-16T16:05:03.613731Z'
epss: 0.00323
epssPercentile: 0.22695
ingestedAt: '2026-06-29T13:24:34.371Z'
patched:
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - enterprise_linux_baseos_eus_v_10_0
  - enterprise_linux_baseos_v_10
  - enterprise_linux_baseos_v_8
  - enterprise_linux_baseos_eus_v_9_6
  - enterprise_linux_baseos_v_9
  - enterprise_linux_codeready_linux_builder_eus_v_10_0
  - enterprise_linux_codeready_linux_builder_v_10
  - discovery 2
  - hardened_images
  - insights_proxy 1.5
  - update_infrastructure 5
---

## Overview

A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.

## Affected

- `jboss_core_services`
- `openshift_container_platform = 4.0`
- `enterprise_linux = 6.0`
- `enterprise_linux = 7.0`
- `enterprise_linux = 8.0`
- `enterprise_linux = 9.0`
- `enterprise_linux = 10.0`
- `libxml2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:70596** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux BaseOS EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70596)
- **RHSA-2026:39304** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-07-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:39304)
- **RHSA-2026:36734** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux BaseOS (v. 8) · released 2026-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:36734)
- **RHSA-2026:70639** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat Enterprise Linux BaseOS EUS (v.9.6) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70639)
- **RHSA-2026:39317** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9) · released 2026-07-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:39317)
- **RHSA-2026:46836** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-07-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:46836)
- **RHSA-2026:7519** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-04-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:7519)
- **RHSA-2026:53371** · Red Hat · fixed in: Red Hat Insights proxy 1.5 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53371)
- **RHSA-2026:44481** · Red Hat · fixed in: Red Hat Update Infrastructure 5 · released 2026-07-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:44481)
- **RHSA-2026:58981** · Red Hat · fixed in: Red Hat Update Infrastructure 5 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58981)
- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat JBoss Core Services, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat JBoss Core Services, Red Hat OpenShift Container Platform 4 · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6170.json)
