7.5highHigh
CVE-2025-7424
Xmlsoft Libxslt
A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt memory. In some cases, it may lead to denial of service or unexpected behavior.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, no account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 7.5 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Weakness
- CWE-843
- Assigned by
- secalert@redhat.com
Dates
- Published
- 2025-07-10
- Last modified
- 2026-09-01
- Sources
- NVD
Affected products
- Xmlsoft Libxsltall versions
- Redhat Openshift Container Platform4.0
- Redhat Enterprise Linux6.0, 7.0, 8.0, 9.0, 10.0
As listed in the NVD configuration data. Not a statement about your estate.
References
- https://access.redhat.com/errata/RHBA-2025:12345
- https://access.redhat.com/errata/RHSA-2026:11015
- https://access.redhat.com/security/cve/CVE-2025-7424
- https://bugzilla.redhat.com/show_bug.cgi?id=2379228
- https://gitlab.gnome.org/GNOME/libxslt/-/issues/139
- http://seclists.org/fulldisclosure/2025/Aug/0
- http://seclists.org/fulldisclosure/2025/Jul/30
- http://seclists.org/fulldisclosure/2025/Jul/32
- http://seclists.org/fulldisclosure/2025/Jul/33
- http://seclists.org/fulldisclosure/2025/Jul/35
- http://seclists.org/fulldisclosure/2025/Jul/37
- http://www.openwall.com/lists/oss-security/2025/07/11/2
- https://lists.debian.org/debian-lts-announce/2025/09/msg00024.html