关键漏洞信息 漏洞概述 类型/严重性: 重要安全更新 主题: libxml2 安全更新,影响 Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions 和 Red Hat Enterprise Linux 8.6 Telecommunications Update Service。 漏洞描述 libxml2 库存在以下安全问题: CVE-2025-32414: Out-of-Bounds Read in libxml2 CVE-2025-49794: Heap use after free (UAF) 导致拒绝服务 (DoS) CVE-2025-49796: Type confusion 导致拒绝服务 (DoS) CVE-2025-6021: Integer Overflow in xmlBuildQName() 导致 Stack Buffer Overflow in libxml2 影响的产品 Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.6 x86_64 解决方案 参考文章: https://access.redhat.com/articles/11258 相关 CVEs CVE-2025-6021 CVE-2025-32414 CVE-2025-49794 CVE-2025-49796