IBM Support

IJ55266: POTENTIAL SECURITY ISSUE LIBXML2_ADVISORY9.ASC

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available.

Notify me when this APAR changes.

 

APAR status

  • Closed as program error.

Error description

  • Vulnerabilities in libxml2 could cause
    a denial of service or other possible undefined
    behavior (CVE-2025-49796, CVE-2025-49794,
    CVE-2025-49795, CVE-2025-6021). AIX uses
    libxml2 as part of its XML parsing functions.
    

Local fix

Problem summary

Problem conclusion

  • Removed security issue.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IJ55266

  • Reported component name

    AIX V7.2

  • Reported component ID

    5765CD200

  • Reported release

    720

  • Status

    CLOSED PER

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2025-07-14

  • Closed date

    2025-07-14

  • Last modified date

    2025-08-14

Fix information

  • Fixed component name

    AIX V7.2

  • Fixed component ID

    5765CD200

Applicable component levels

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SG11S","label":"AIX 7.2 HIPERS- APARs and Fixes"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"720","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}}]

Document Information

Modified date:
15 August 2025