CVE-2025-7425

HIGH

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.

CVSS v3.1 Score

7.8
HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
Attack Vector
LOCAL
Complexity
HIGH
Privileges
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH
Published: 7/10/2025Modified: 5/12/2026

Related Intelligence (1)

References (44)

https://access.redhat.com/errata/RHBA-2025:12345https://access.redhat.com/errata/RHSA-2025:12447https://access.redhat.com/errata/RHSA-2025:12450https://access.redhat.com/errata/RHSA-2025:13267https://access.redhat.com/errata/RHSA-2025:13308https://access.redhat.com/errata/RHSA-2025:13309https://access.redhat.com/errata/RHSA-2025:13310https://access.redhat.com/errata/RHSA-2025:13311https://access.redhat.com/errata/RHSA-2025:13312https://access.redhat.com/errata/RHSA-2025:13313https://access.redhat.com/errata/RHSA-2025:13314https://access.redhat.com/errata/RHSA-2025:13335https://access.redhat.com/errata/RHSA-2025:13464https://access.redhat.com/errata/RHSA-2025:13622https://access.redhat.com/errata/RHSA-2025:14059https://access.redhat.com/errata/RHSA-2025:14396https://access.redhat.com/errata/RHSA-2025:14818https://access.redhat.com/errata/RHSA-2025:14819https://access.redhat.com/errata/RHSA-2025:14853https://access.redhat.com/errata/RHSA-2025:14858https://access.redhat.com/errata/RHSA-2025:15308https://access.redhat.com/errata/RHSA-2025:15672https://access.redhat.com/errata/RHSA-2025:15827https://access.redhat.com/errata/RHSA-2025:15828https://access.redhat.com/errata/RHSA-2025:18219https://access.redhat.com/errata/RHSA-2025:21885https://access.redhat.com/errata/RHSA-2025:21913https://access.redhat.com/errata/RHSA-2026:0934https://access.redhat.com/errata/RHSA-2026:11503https://access.redhat.com/security/cve/CVE-2025-7425https://bugzilla.redhat.com/show_bug.cgi?id=2379274https://gitlab.gnome.org/GNOME/libxslt/-/issues/140http://seclists.org/fulldisclosure/2025/Aug/0http://seclists.org/fulldisclosure/2025/Jul/30http://seclists.org/fulldisclosure/2025/Jul/32http://seclists.org/fulldisclosure/2025/Jul/35http://seclists.org/fulldisclosure/2025/Jul/37http://www.openwall.com/lists/oss-security/2025/07/11/2https://lists.debian.org/debian-lts-announce/2025/09/msg00035.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-032379.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-265688.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-577017.htmlhttps://gitlab.gnome.org/GNOME/libxslt/-/issues/140