CVE-2025-6170

Executive Summary

CVE-2025-6170: The xmllint interactive shell does not enforce input length limits, allowing an attacker to supply an overly long command that can crash the tool or, in rare configurations lacking modern mitigations, lead to arbitrary code execution. The flaw can be leveraged for denial‑of‑service or potential remote code execution. No current CISA KEV listing; mitigations include patching, input validation, or disabling the interactive shell.


Authoritative CVE Metadata - CVSS Base Score: 2.5 (LOW) - Published: 2025-06-16T16:15:20.430 - Last Modified: 2026-09-29T01:16:43.450

Original Description: A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.

"The possession of knowledge does not kill the sense of wonder and mystery. There is always more mystery."

— Anais Nin
Source: NVD