View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0012013 | Rocky-Linux-8 | libxml2 | public | 2026-02-16 04:49 | 2026-02-16 05:05 |
| Reporter | Chris Van de Velde | Assigned To | Louis Abel | ||
| Priority | normal | Severity | major | Reproducibility | always |
| Status | resolved | Resolution | no change required | ||
| Summary | 0012013: CVE-2025-7425 missing from Rocky8 errata | ||||
| Description | Was fixed some time ago in Redhat 8: https://access.redhat.com/security/cve/cve-2025-7425 (August 2025) Rocky 9 has picked up the fix: https://errata.rockylinux.org/RLSA-2025:12447 Current builds show #12 27.72 libxml2 x86_64 2.9.7-21.el8_10.3 baseos 697 k | ||||
| Tags | No tags attached. | ||||
| Also should fix CVE-2024-56171, CVE-2025-24928, CVE-2025-49794, CVE-2025-49796, CVE-2025-6021 | |
|
2.9.7-21.el8_10.3 is the most up to date version that applies all previous fixes, filed as RLSA-2025:13203. Please see the change log below. ``` * Tue Aug 05 2025 David King <dking@redhat.com> - 2.9.7.21.3 - Fix CVE-2025-32415 (RHEL-100177) * Mon Jul 21 2025 David King <dking@redhat.com> - 2.9.7.21.2 - Fix CVE-2025-7425 (RHEL-102797) * Mon Jun 16 2025 David King <dking@redhat.com> - 2.9.7-21.1 - Fix CVE-2025-6021 (RHEL-96498) - Fix CVE-2025-49794 (RHEL-96398) - Fix CVE-2025-49796 (RHEL-96424) * Fri Jun 13 2025 David King <dking@redhat.com> - 2.9.7-21 - Fix integer overflow (RHEL-74345) * Thu Jun 05 2025 David King <dking@redhat.com> - 2.9.7-20 - Fix CVE-2025-32414 (RHEL-88198) * Tue Mar 11 2025 Michael Catanzaro <mcatanzaro@redhat.com> - 2.9.7-19 - Fix CVE-2024-56171 (RHEL-80122) - Fix CVE-2025-24928 (RHEL-80137) ``` RLSA-2025:13203 is the current errata that pulls in the latest libxml2 for 8. If you are expecting older errata (which is almost never recommended with updates that supersede the previous), you likely won't see them. You may report those issues here: https://github.com/resf/distro-tools/issues |
|
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2026-02-16 04:49 | Chris Van de Velde | New Issue | |
| 2026-02-16 04:54 | Chris Van de Velde | Note Added: 0012772 | |
| 2026-02-16 05:05 | Louis Abel | Assigned To | => Louis Abel |
| 2026-02-16 05:05 | Louis Abel | Status | new => resolved |
| 2026-02-16 05:05 | Louis Abel | Resolution | open => no change required |
| 2026-02-16 05:05 | Louis Abel | Note Added: 0012805 |