CVE Database
/

CVE-2025-7425

Back to search

CVE-2025-7425

Published: Jul 10, 2025

Modified: Jun 2, 2026

PUBLISHED

CVSS v3.1

7.8

HIGH

Description

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.

VendorProductVersions

GNOME

libxml2

affected
0 - < 2.15.2

Red Hat

Red Hat Enterprise Linux 10

unaffected
0:2.12.5-8.el10_0 - < *

Red Hat

Red Hat Enterprise Linux 10

unaffected
0:1.1.39-8.el10_0 - < *

Red Hat

Red Hat Enterprise Linux 7 Extended Lifecycle Support

unaffected
0:2.9.1-6.el7_9.12 - < *

Red Hat

Red Hat Enterprise Linux 8

unaffected
0:2.9.7-21.el8_10.2 - < *

Red Hat

Red Hat Enterprise Linux 8

unaffected
0:2.9.7-21.el8_10.2 - < *

Red Hat

Red Hat Enterprise Linux 8.2 Advanced Update Support

unaffected
0:2.9.7-9.el8_2.4 - < *

Red Hat

Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support

unaffected
0:2.9.7-9.el8_4.7 - < *

Red Hat

Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

unaffected
0:2.9.7-9.el8_4.7 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support

unaffected
0:2.9.7-13.el8_6.11 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Telecommunications Update Service

unaffected
0:2.9.7-13.el8_6.11 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions

unaffected
0:2.9.7-13.el8_6.11 - < *

Red Hat

Red Hat Enterprise Linux 8.8 Telecommunications Update Service

unaffected
0:2.9.7-16.el8_8.10 - < *

Red Hat

Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions

unaffected
0:2.9.7-16.el8_8.10 - < *

Red Hat

Red Hat Enterprise Linux 9

unaffected
0:2.9.13-11.el9_6 - < *

Red Hat

Red Hat Enterprise Linux 9

unaffected
0:2.9.13-11.el9_6 - < *

Red Hat

Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

unaffected
0:2.9.13-1.el9_0.6 - < *

Red Hat

Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

unaffected
0:2.9.13-3.el9_2.8 - < *

Red Hat

Red Hat Enterprise Linux 9.4 Extended Update Support

unaffected
0:2.9.13-11.el9_4 - < *

Red Hat

Red Hat OpenShift Container Platform 4.12

unaffected
412.86.202509030110-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.13

unaffected
413.92.202509030117-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.14

unaffected
414.92.202508270040-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.15

unaffected
415.92.202508192014-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.16

unaffected
416.94.202508261955-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.17

unaffected
417.94.202508141510-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.18

unaffected
418.94.202508261658-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.19

unaffected
4.19.9.6.202508271124-0 - < *

Red Hat

Red Hat Web Terminal 1.11 on RHEL 9

unaffected
1.11-19 - < *

Red Hat

Red Hat Web Terminal 1.11 on RHEL 9

unaffected
1.11-8 - < *

Red Hat

Red Hat Web Terminal 1.12 on RHEL 9

unaffected
1.12-4 - < *

Red Hat

RHOSS-1.36-RHEL-8

unaffected
1.36.0-11 - < *

Red Hat

RHOSS-1.36-RHEL-8

unaffected
1.36.0-11 - < *

Red Hat

RHOSS-1.36-RHEL-8

unaffected
1.36.0-11 - < *

Red Hat

RHOSS-1.36-RHEL-8

unaffected
1.36.0-10 - < *

Red Hat

RHOSS-1.36-RHEL-8

unaffected
1.36.0-10 - < *

Red Hat

RHOSS-1.36-RHEL-8

unaffected
1.36.0-4 - < *

Red Hat

RHOSS-1.36-RHEL-8

unaffected
1.36.0-9 - < *

Red Hat

RHOSS-1.36-RHEL-8

unaffected
1.36.0-12 - < *

Red Hat

RHOSS-1.36-RHEL-8

unaffected
1.36.0-18 - < *

Red Hat

RHOSS-1.36-RHEL-8

unaffected
1.36.0-11 - < *

Red Hat

RHOSS-1.36-RHEL-8

unaffected
1.36.0-7 - < *

Red Hat

cert-manager operator for Red Hat OpenShift 1.16

unaffected
v1.16.5-1760515757 - < *

Red Hat

File Integrity Operator 1

unaffected
v1.3 - < *

Red Hat

OpenShift Compliance Operator 1

unaffected
1.8.0 - < *

Red Hat

OpenShift Compliance Operator 1

unaffected
1.8.0 - < *

Red Hat

OpenShift Compliance Operator 1

unaffected
1.8.0 - < *

Red Hat

Red Hat Discovery 2

unaffected
2.0.1-1754478727 - < *

Red Hat

Red Hat Hardened Images

unaffected
2.15.3-0.1.hum1 - < *

Red Hat

Red Hat Insights proxy 1.5

unaffected
1.5.5-1754504343 - < *

Red Hat

Red Hat OpenShift distributed tracing 3.5.1

unaffected
rhosdt-3.5-1754559657 - < *

Red Hat

Red Hat OpenShift distributed tracing 3.5.1

unaffected
rhosdt-3.5-1754559845 - < *

Red Hat

Red Hat OpenShift distributed tracing 3.5.1

unaffected
rhosdt-3.5-1754559691 - < *

Red Hat

Red Hat OpenShift distributed tracing 3.5.1

unaffected
rhosdt-3.5-1754559660 - < *

Red Hat

Red Hat OpenShift distributed tracing 3.5.1

unaffected
rhosdt-3.5-1754559663 - < *

Red Hat

Red Hat OpenShift distributed tracing 3.5.1

unaffected
rhosdt-3.5-1754559657 - < *

Red Hat

Red Hat OpenShift distributed tracing 3.5.1

unaffected
rhosdt-3.5-1754569861 - < *

Red Hat

Red Hat OpenShift distributed tracing 3.5.1

unaffected
rhosdt-3.5-1754559846 - < *

Red Hat

Red Hat OpenShift distributed tracing 3.5.1

unaffected
rhosdt-3.5-1754559651 - < *

Red Hat

Red Hat Enterprise Linux 6

All versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H

Attack Vector

Local

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

None

Integrity

High

Availability

High

References

RHBA-2025:12345
vendor-advisory
x_refsource_REDHAT
RHSA-2025:12447
vendor-advisory
x_refsource_REDHAT
RHSA-2025:12450
vendor-advisory
x_refsource_REDHAT
RHSA-2025:13267
vendor-advisory
x_refsource_REDHAT
RHSA-2025:13308
vendor-advisory
x_refsource_REDHAT
RHSA-2025:13309
vendor-advisory
x_refsource_REDHAT
RHSA-2025:13310
vendor-advisory
x_refsource_REDHAT
RHSA-2025:13311
vendor-advisory
x_refsource_REDHAT
RHSA-2025:13312
vendor-advisory
x_refsource_REDHAT
RHSA-2025:13313
vendor-advisory
x_refsource_REDHAT
RHSA-2025:13314
vendor-advisory
x_refsource_REDHAT
RHSA-2025:13335
vendor-advisory
x_refsource_REDHAT
RHSA-2025:13464
vendor-advisory
x_refsource_REDHAT
RHSA-2025:13622
vendor-advisory
x_refsource_REDHAT
RHSA-2025:14059
vendor-advisory
x_refsource_REDHAT
RHSA-2025:14396
vendor-advisory
x_refsource_REDHAT
RHSA-2025:14818
vendor-advisory
x_refsource_REDHAT
RHSA-2025:14819
vendor-advisory
x_refsource_REDHAT
RHSA-2025:14853
vendor-advisory
x_refsource_REDHAT
RHSA-2025:14858
vendor-advisory
x_refsource_REDHAT
RHSA-2025:15308
vendor-advisory
x_refsource_REDHAT
RHSA-2025:15672
vendor-advisory
x_refsource_REDHAT
RHSA-2025:15827
vendor-advisory
x_refsource_REDHAT
RHSA-2025:15828
vendor-advisory
x_refsource_REDHAT
RHSA-2025:18219
vendor-advisory
x_refsource_REDHAT
RHSA-2025:21885
vendor-advisory
x_refsource_REDHAT
RHSA-2025:21913
vendor-advisory
x_refsource_REDHAT
RHSA-2026:0934
vendor-advisory
x_refsource_REDHAT
RHSA-2026:11503
vendor-advisory
x_refsource_REDHAT
RHBZ#2379274
issue-tracking
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now