Skip to main content
Skip table of contents

ISN 2025-08: Libxml2 Vulnerabilities

Updated 2 December 2025 (OS 12 fix version)

CVSS 3.1: 7.9 (High)

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Summary

Security vulnerabilities have been found in Libxml2, an XML library used in IGEL OS. This affects the following product versions:

  • IGEL OS 12

  • IGEL OS 11

Details

Libxml2 is affected by a use-after-free issue that can be triggered by a crafted XML document (CVE-2024-56171). Besides that, a stack-based buffer overflow can occur during DTD validation with an untrusted DTD or document (CVE-2025-24928, high).

Update Instructions

  • OS 12: Update to the IGEL OS base system 12.7.0.

  • OS 11: Update to OS 11.11.100.

References

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.