View Issue Details

IDProjectCategoryView StatusLast Update
0012013Rocky-Linux-8libxml2public2026-02-16 05:05
ReporterChris Van de Velde Assigned ToLouis Abel  
PrioritynormalSeveritymajorReproducibilityalways
Status resolvedResolutionno change required 
Summary0012013: CVE-2025-7425 missing from Rocky8 errata
DescriptionWas fixed some time ago in Redhat 8: https://access.redhat.com/security/cve/cve-2025-7425 (August 2025)
Rocky 9 has picked up the fix: https://errata.rockylinux.org/RLSA-2025:12447

Current builds show #12 27.72 libxml2 x86_64 2.9.7-21.el8_10.3 baseos 697 k
TagsNo tags attached.

Activities

Chris Van de Velde

Chris Van de Velde

2026-02-16 04:54

reporter   ~0012772

Also should fix CVE-2024-56171, CVE-2025-24928, CVE-2025-49794, CVE-2025-49796, CVE-2025-6021
Louis Abel

Louis Abel

2026-02-16 05:05

administrator   ~0012805

2.9.7-21.el8_10.3 is the most up to date version that applies all previous fixes, filed as RLSA-2025:13203.

Please see the change log below.

```
* Tue Aug 05 2025 David King <dking@redhat.com> - 2.9.7.21.3
- Fix CVE-2025-32415 (RHEL-100177)

* Mon Jul 21 2025 David King <dking@redhat.com> - 2.9.7.21.2
- Fix CVE-2025-7425 (RHEL-102797)

* Mon Jun 16 2025 David King <dking@redhat.com> - 2.9.7-21.1
- Fix CVE-2025-6021 (RHEL-96498)
- Fix CVE-2025-49794 (RHEL-96398)
- Fix CVE-2025-49796 (RHEL-96424)

* Fri Jun 13 2025 David King <dking@redhat.com> - 2.9.7-21
- Fix integer overflow (RHEL-74345)

* Thu Jun 05 2025 David King <dking@redhat.com> - 2.9.7-20
- Fix CVE-2025-32414 (RHEL-88198)

* Tue Mar 11 2025 Michael Catanzaro <mcatanzaro@redhat.com> - 2.9.7-19
- Fix CVE-2024-56171 (RHEL-80122)
- Fix CVE-2025-24928 (RHEL-80137)
```

RLSA-2025:13203 is the current errata that pulls in the latest libxml2 for 8. If you are expecting older errata (which is almost never recommended with updates that supersede the previous), you likely won't see them. You may report those issues here: https://github.com/resf/distro-tools/issues

Issue History

Date Modified Username Field Change
2026-02-16 04:49 Chris Van de Velde New Issue
2026-02-16 04:54 Chris Van de Velde Note Added: 0012772
2026-02-16 05:05 Louis Abel Assigned To => Louis Abel
2026-02-16 05:05 Louis Abel Status new => resolved
2026-02-16 05:05 Louis Abel Resolution open => no change required
2026-02-16 05:05 Louis Abel Note Added: 0012805