CVE-2025-7425
HIGHA flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
Published: 7/10/2025Modified: 5/12/2026
References (44)
https://access.redhat.com/errata/RHBA-2025:12345https://access.redhat.com/errata/RHSA-2025:12447https://access.redhat.com/errata/RHSA-2025:12450https://access.redhat.com/errata/RHSA-2025:13267https://access.redhat.com/errata/RHSA-2025:13308https://access.redhat.com/errata/RHSA-2025:13309https://access.redhat.com/errata/RHSA-2025:13310https://access.redhat.com/errata/RHSA-2025:13311https://access.redhat.com/errata/RHSA-2025:13312https://access.redhat.com/errata/RHSA-2025:13313https://access.redhat.com/errata/RHSA-2025:13314https://access.redhat.com/errata/RHSA-2025:13335https://access.redhat.com/errata/RHSA-2025:13464https://access.redhat.com/errata/RHSA-2025:13622https://access.redhat.com/errata/RHSA-2025:14059https://access.redhat.com/errata/RHSA-2025:14396https://access.redhat.com/errata/RHSA-2025:14818https://access.redhat.com/errata/RHSA-2025:14819https://access.redhat.com/errata/RHSA-2025:14853https://access.redhat.com/errata/RHSA-2025:14858https://access.redhat.com/errata/RHSA-2025:15308https://access.redhat.com/errata/RHSA-2025:15672https://access.redhat.com/errata/RHSA-2025:15827https://access.redhat.com/errata/RHSA-2025:15828https://access.redhat.com/errata/RHSA-2025:18219https://access.redhat.com/errata/RHSA-2025:21885https://access.redhat.com/errata/RHSA-2025:21913https://access.redhat.com/errata/RHSA-2026:0934https://access.redhat.com/errata/RHSA-2026:11503https://access.redhat.com/security/cve/CVE-2025-7425https://bugzilla.redhat.com/show_bug.cgi?id=2379274https://gitlab.gnome.org/GNOME/libxslt/-/issues/140http://seclists.org/fulldisclosure/2025/Aug/0http://seclists.org/fulldisclosure/2025/Jul/30http://seclists.org/fulldisclosure/2025/Jul/32http://seclists.org/fulldisclosure/2025/Jul/35http://seclists.org/fulldisclosure/2025/Jul/37http://www.openwall.com/lists/oss-security/2025/07/11/2https://lists.debian.org/debian-lts-announce/2025/09/msg00035.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-032379.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-265688.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-577017.htmlhttps://gitlab.gnome.org/GNOME/libxslt/-/issues/140