
🚨 HIGH - libxml2 XPath NULL pointer dereference DoS (CVE-2025-49795) A NULL pointer dereference flaw exists in libxml2’s XPath expression processing logic when parsing/evaluating XPath within XML documents. The root cause is improper NULL handling (NULL pointer dereference) in the XPath code path during expression evaluation. An attacker can exploit this by sending crafted malicious XML/XPath input to any application or service that processes untrusted XML with libxml2, typically requiring no special privileges beyond the ability to supply XML. If triggered, the vulnerable process can crash, resulting in denial of service and potential service instability for upstream applications. 👉 Affected: libxml2, libxml2-main (version range not specified) | Upgrade to vendor-fixed version when available (or backported security release for your distro)
Post summary
The advisory announces a high‑severity NULL pointer dereference DoS vulnerability in libxml2’s XPath processing and recommends upgrading to the vendor‑fixed or backported version to mitigate the risk.
