CVE-2025-49794: Red Hat Cert-Manager Operator For Red Hat Openshift 1.16

Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.

A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.

Affected products

  • Red Hat Cert-Manager Operator For Red Hat Openshift 1.16: before v1.16.5-1760515757 (fixed in v1.16.5-1760515757)
  • Red Hat Openshift File Integrity Operator - Fio 1: before v1.3 (fixed in v1.3)
  • Red Hat Red Hat Enterprise Linux 10: before 0:2.12.5-7.el10_0 (fixed in 0:2.12.5-7.el10_0)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:2.9.1-6.el7_9.10 (fixed in 0:2.9.1-6.el7_9.10)
  • Red Hat Red Hat Enterprise Linux 8: before 0:2.9.7-21.el8_10.1 (fixed in 0:2.9.7-21.el8_10.1)
  • Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support: before 0:2.9.7-9.el8_2.3 (fixed in 0:2.9.7-9.el8_2.3)
  • Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:2.9.7-9.el8_4.6 (fixed in 0:2.9.7-9.el8_4.6)
  • Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 0:2.9.7-9.el8_4.6 (fixed in 0:2.9.7-9.el8_4.6)
  • Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:2.9.7-13.el8_6.10 (fixed in 0:2.9.7-13.el8_6.10)
  • Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service: before 0:2.9.7-13.el8_6.10 (fixed in 0:2.9.7-13.el8_6.10)
  • Red Hat Red Hat Enterprise Linux 8.6 Update Services For SAP Solutions: before 0:2.9.7-13.el8_6.10 (fixed in 0:2.9.7-13.el8_6.10)
  • Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 0:2.9.7-16.el8_8.9 (fixed in 0:2.9.7-16.el8_8.9)
  • Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 0:2.9.7-16.el8_8.9 (fixed in 0:2.9.7-16.el8_8.9)
  • Red Hat Red Hat Enterprise Linux 9: before 0:2.9.13-10.el9_6 (fixed in 0:2.9.13-10.el9_6)
  • Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 0:2.9.13-1.el9_0.5 (fixed in 0:2.9.13-1.el9_0.5)
  • Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:2.9.13-3.el9_2.7 (fixed in 0:2.9.13-3.el9_2.7)
  • Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 0:2.9.13-10.el9_4 (fixed in 0:2.9.13-10.el9_4)
  • Red Hat Red Hat Hardened Images: before 2.15.2-0.3.hum1 (fixed in 2.15.2-0.3.hum1)
  • Red Hat Red Hat Insights Proxy 1.5: before 1.5.5-1754504343 (fixed in 1.5.5-1754504343)
  • Red Hat Red Hat JBoss Core Services 2.4.62.sp2
  • Red Hat Red Hat Openshift Container Platform 4.12: before 412.86.202510291903-0 (fixed in 412.86.202510291903-0)
  • Red Hat Red Hat Openshift Container Platform 4.13: before 413.92.202510150118-0 (fixed in 413.92.202510150118-0)
  • Red Hat Red Hat Openshift Container Platform 4.14: before 414.92.202510211419-0 (fixed in 414.92.202510211419-0)
  • Red Hat Red Hat Openshift Container Platform 4.15: before 415.92.202609140326-0 (fixed in 415.92.202609140326-0)
  • and 20 more

Published 2025-06-16. Last modified 2026-10-08.