{"id":"DEBIAN-CVE-2025-12863","details":"A flaw was found in the xmlSetTreeDoc() function of the libxml2 XML parsing library. This function is responsible for updating document pointers when XML nodes are moved between documents. Due to improper handling of namespace references, a namespace pointer may remain linked to a freed memory region when the original document is destroyed. As a result, subsequent operations that access the namespace can lead to a use-after-free condition, causing an application crash.","modified":"2025-11-21T01:48:21.347798Z","published":"2025-11-07T21:15:40.393Z","withdrawn":"2025-11-21T01:48:21.347798Z","upstream":["CVE-2025-12863"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-12863"}],"affected":[{"package":{"name":"libxml2","ecosystem":"Debian:11","purl":"pkg:deb/debian/libxml2?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.12.3+dfsg-0exp1","2.12.5+dfsg-0exp1","2.12.6+dfsg-0exp1","2.12.6+dfsg-0exp2","2.12.7+dfsg+really2.9.14-0.1","2.12.7+dfsg+really2.9.14-0.2","2.12.7+dfsg+really2.9.14-0.3","2.12.7+dfsg+really2.9.14-0.4","2.12.7+dfsg+really2.9.14-1","2.12.7+dfsg+really2.9.14-2","2.12.7+dfsg+really2.9.14-2.1","2.12.7+dfsg-1","2.12.7+dfsg-2","2.12.7+dfsg-3","2.13.1+dfsg-0exp1","2.13.3+dfsg-0exp1","2.13.3+dfsg-0exp2","2.14.1+dfsg-0exp1","2.14.2+dfsg-0exp1","2.14.3+dfsg-0exp1","2.14.3+dfsg-0exp2","2.14.3+dfsg-0exp3","2.14.4+dfsg-0exp1","2.14.5+dfsg-0.1","2.14.5+dfsg-0.2","2.14.5+dfsg-0exp1","2.14.5+dfsg-0exp2","2.14.6+dfsg-0.1","2.15.0+dfsg-0.1","2.15.0+dfsg-0.2","2.15.0+dfsg-0.3","2.15.1+dfsg-0.1","2.15.1+dfsg-0.2","2.15.1+dfsg-0.3","2.15.1+dfsg-0.4","2.9.10+dfsg-6.7","2.9.10+dfsg-6.7+deb11u1","2.9.10+dfsg-6.7+deb11u2","2.9.10+dfsg-6.7+deb11u3","2.9.10+dfsg-6.7+deb11u4","2.9.10+dfsg-6.7+deb11u5","2.9.10+dfsg-6.7+deb11u6","2.9.10+dfsg-6.7+deb11u7","2.9.10+dfsg-6.7+deb11u8","2.9.10+dfsg-6.7+deb11u9","2.9.12+dfsg-1","2.9.12+dfsg-2","2.9.12+dfsg-3","2.9.12+dfsg-4","2.9.12+dfsg-5","2.9.12+dfsg-6","2.9.13+dfsg-1","2.9.14+dfsg-1","2.9.14+dfsg-1.1","2.9.14+dfsg-1.2","2.9.14+dfsg-1.3","2.9.14+dfsg-1.3~deb12u1","2.9.14+dfsg-1.3~deb12u2","2.9.14+dfsg-1.3~deb12u3","2.9.14+dfsg-1.3~deb12u4"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-12863.json"}},{"package":{"name":"libxml2","ecosystem":"Debian:12","purl":"pkg:deb/debian/libxml2?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.12.3+dfsg-0exp1","2.12.5+dfsg-0exp1","2.12.6+dfsg-0exp1","2.12.6+dfsg-0exp2","2.12.7+dfsg+really2.9.14-0.1","2.12.7+dfsg+really2.9.14-0.2","2.12.7+dfsg+really2.9.14-0.3","2.12.7+dfsg+really2.9.14-0.4","2.12.7+dfsg+really2.9.14-1","2.12.7+dfsg+really2.9.14-2","2.12.7+dfsg+really2.9.14-2.1","2.12.7+dfsg-1","2.12.7+dfsg-2","2.12.7+dfsg-3","2.13.1+dfsg-0exp1","2.13.3+dfsg-0exp1","2.13.3+dfsg-0exp2","2.14.1+dfsg-0exp1","2.14.2+dfsg-0exp1","2.14.3+dfsg-0exp1","2.14.3+dfsg-0exp2","2.14.3+dfsg-0exp3","2.14.4+dfsg-0exp1","2.14.5+dfsg-0.1","2.14.5+dfsg-0.2","2.14.5+dfsg-0exp1","2.14.5+dfsg-0exp2","2.14.6+dfsg-0.1","2.15.0+dfsg-0.1","2.15.0+dfsg-0.2","2.15.0+dfsg-0.3","2.15.1+dfsg-0.1","2.15.1+dfsg-0.2","2.15.1+dfsg-0.3","2.15.1+dfsg-0.4","2.9.14+dfsg-1.2","2.9.14+dfsg-1.3","2.9.14+dfsg-1.3~deb12u1","2.9.14+dfsg-1.3~deb12u2","2.9.14+dfsg-1.3~deb12u3","2.9.14+dfsg-1.3~deb12u4"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-12863.json"}},{"package":{"name":"libxml2","ecosystem":"Debian:13","purl":"pkg:deb/debian/libxml2?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.12.7+dfsg+really2.9.14-2.1","2.12.7+dfsg+really2.9.14-2.1+deb13u1","2.12.7+dfsg+really2.9.14-2.1+deb13u2","2.13.1+dfsg-0exp1","2.13.3+dfsg-0exp1","2.13.3+dfsg-0exp2","2.14.1+dfsg-0exp1","2.14.2+dfsg-0exp1","2.14.3+dfsg-0exp1","2.14.3+dfsg-0exp2","2.14.3+dfsg-0exp3","2.14.4+dfsg-0exp1","2.14.5+dfsg-0.1","2.14.5+dfsg-0.2","2.14.5+dfsg-0exp1","2.14.5+dfsg-0exp2","2.14.6+dfsg-0.1","2.15.0+dfsg-0.1","2.15.0+dfsg-0.2","2.15.0+dfsg-0.3","2.15.1+dfsg-0.1","2.15.1+dfsg-0.2","2.15.1+dfsg-0.3","2.15.1+dfsg-0.4"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-12863.json"}},{"package":{"name":"libxml2","ecosystem":"Debian:14","purl":"pkg:deb/debian/libxml2?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.15.1+dfsg-0.4"}]}],"versions":["2.12.7+dfsg+really2.9.14-2.1","2.13.1+dfsg-0exp1","2.13.3+dfsg-0exp1","2.13.3+dfsg-0exp2","2.14.1+dfsg-0exp1","2.14.2+dfsg-0exp1","2.14.3+dfsg-0exp1","2.14.3+dfsg-0exp2","2.14.3+dfsg-0exp3","2.14.4+dfsg-0exp1","2.14.5+dfsg-0.1","2.14.5+dfsg-0.2","2.14.5+dfsg-0exp1","2.14.5+dfsg-0exp2","2.14.6+dfsg-0.1","2.15.0+dfsg-0.1","2.15.0+dfsg-0.2","2.15.0+dfsg-0.3","2.15.1+dfsg-0.1","2.15.1+dfsg-0.2","2.15.1+dfsg-0.3"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-12863.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}