CVE-2025-7424

A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt memory. In some cases, it may lead to denial of service or unexpected behavior.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2025-7424 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2379228 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:xmlsoft:libxslt:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

27 Aug 2025, 18:00

Type Values Removed Values Added
First Time Xmlsoft
Redhat enterprise Linux
Xmlsoft libxslt
Redhat
Redhat openshift Container Platform
CPE cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxslt:-:*:*:*:*:*:*:*
References () https://access.redhat.com/security/cve/CVE-2025-7424 - () https://access.redhat.com/security/cve/CVE-2025-7424 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2379228 - () https://bugzilla.redhat.com/show_bug.cgi?id=2379228 - Issue Tracking, Third Party Advisory

15 Jul 2025, 13:24

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en la librería libxslt. El mismo campo de memoria, psvi, se utiliza tanto para la hoja de estilo como para los datos de entrada, lo que puede provocar confusión de tipos durante las transformaciones XML. Esta vulnerabilidad permite a un atacante bloquear la aplicación o corromper la memoria. En algunos casos, puede provocar una denegación de servicio o un comportamiento inesperado.

10 Jul 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-10 14:15

Updated : 2025-08-27 18:00


NVD link : CVE-2025-7424

Mitre link : CVE-2025-7424

CVE.ORG link : CVE-2025-7424


JSON object : View

Products Affected

redhat

  • openshift_container_platform
  • enterprise_linux

xmlsoft

  • libxslt
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')