CVE-2025-6170
LOWA flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare...
Full CISO analysis pending enrichment.
What systems are affected?
How severe is it?
What is the attack surface?
What should I do?
No patch available
Monitor for updates. Consider compensating controls or temporary mitigations.
Which compliance frameworks are affected?
Compliance analysis pending. Sign in for full compliance mapping when available.
Frequently Asked Questions
What is CVE-2025-6170?
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
Is CVE-2025-6170 actively exploited?
No confirmed active exploitation of CVE-2025-6170 has been reported, but organizations should still patch proactively.
How to fix CVE-2025-6170?
No patch is currently available. Monitor vendor advisories for updates.
What is the CVSS score for CVE-2025-6170?
CVE-2025-6170 has a CVSS v3.1 base score of 2.5 (LOW).
What are the technical details?
Original Advisory
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
Weaknesses (CWE)
CWE-121 — Stack-based Buffer Overflow: A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
- [Operation, Build and Compilation] Use automatic buffer overflow detection mechanisms that are offered by certain compilers or compiler extensions. Examples include: the Microsoft Visual Studio /GS flag, Fedora/Red Hat FORTIFY_SOURCE GCC flag, StackGuard, and ProPolice, which provide various mechanisms including canary-based detection and range/index checking. D3-SFCV (Stack Frame Canary Validation) from D3FEND [REF-1334] discusses canary-based detection in detail.
- [Architecture and Design] Use an abstraction library to abstract away risky APIs. Not a complete solution.
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L References
- access.redhat.com/errata/RHSA-2026:36734 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:39304 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:39317 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:44481 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:46836 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:53371 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:58981 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:70596 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:70639 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:72394 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:72395 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:72399 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:72470 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:72475 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:72476 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:72502 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:73859 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:73909 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:73929 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:73930 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:73959 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:73960 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:73961 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:73962 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:7519 vendor-advisory x_refsource_REDHAT
- access.redhat.com/security/cve/CVE-2025-6170 vdb-entry x_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgi issue-tracking x_refsource_REDHAT
- gitlab.gnome.org/GNOME/libxml2/-/issues/941
Timeline
Related Vulnerabilities
CVE-2026-61732 10.0 Analysis pending
Same package: vllm CVE-2026-25960 9.8 vllm: SSRF allows internal network access
Same package: vllm CVE-2025-47277 9.8 vLLM: RCE via exposed TCPStore in distributed inference
Same package: vllm CVE-2024-11041 9.8 vllm: RCE via unsafe pickle deserialization in MessageQueue
Same package: vllm CVE-2024-9053 9.8 vllm: RCE via unsafe pickle deserialization in RPC server
Same package: vllm