---
id: CVE-2025-7425
title: >-
  A flaw was found in libxslt where the attribute type, atype, flags are
  modified in a way that corrupts internal memory management
summary: >-
  A flaw was found in libxslt where the attribute type, atype, flags are
  modified in a way that corrupts internal memory management. When XSLT
  functions, such as the key() process, result in tree fragments, this
  corruption prevents the pro…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H'
cwe:
  - CWE-416
vendor: GNOME
product: libxml2
affected:
  - libxml2 < 2.15.2
  - libxml2 (all versions)
  - libxslt (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - libxml2 (all versions)
  - rhcos (all versions)
  - rhcos (all versions)
  - rhcos (all versions)
  - rhcos (all versions)
  - rhcos (all versions)
  - rhcos (all versions)
  - rhcos (all versions)
  - rhcos (all versions)
  - web-terminal/web-terminal-rhel9-operator (all versions)
  - web-terminal/web-terminal-tooling-rhel9 (all versions)
  - web-terminal/web-terminal-tooling-rhel9 (all versions)
  - openshift-serverless-1/logic-data-index-ephemeral-rhel8 (all versions)
  - openshift-serverless-1/logic-data-index-postgresql-rhel8 (all versions)
  - openshift-serverless-1/logic-db-migrator-tool-rhel8 (all versions)
  - openshift-serverless-1/logic-jobs-service-ephemeral-rhel8 (all versions)
  - openshift-serverless-1/logic-jobs-service-postgresql-rhel8 (all versions)
  - openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8 (all versions)
  - openshift-serverless-1/logic-management-console-rhel8 (all versions)
  - openshift-serverless-1/logic-operator-bundle (all versions)
  - openshift-serverless-1/logic-rhel8-operator (all versions)
  - openshift-serverless-1/logic-swf-builder-rhel8 (all versions)
  - openshift-serverless-1/logic-swf-devmode-rhel8 (all versions)
  - cert-manager/jetstack-cert-manager-rhel9 (all versions)
  - compliance/openshift-compliance-must-gather-rhel8 (all versions)
  - compliance/openshift-compliance-openscap-rhel8 (all versions)
  - compliance/openshift-compliance-rhel8-operator (all versions)
  - compliance/openshift-file-integrity-rhel8-operator (all versions)
  - discovery/discovery-server-rhel9 (all versions)
  - libxml2-main (all versions)
  - insights-proxy/insights-proxy-container-rhel9 (all versions)
  - rhosdt/jaeger-agent-rhel8 (all versions)
patched:
  - enterprise_linux_server_v_7_els
  - enterprise_linux_server_optional_v_7_els
  - openshift_container_platform 4.12
  - 8base_openshift_serverless_1_36
  - openshift_container_platform 4.13
  - openshift_container_platform 4.14
  - openshift_container_platform 4.15
  - openshift_container_platform 4.16
  - openshift_container_platform 4.17
  - openshift_container_platform 4.18
  - openshift_container_platform 4.19
  - web_terminal_1_11_on_rhel 9
  - web_terminal_1_12_on_rhel 9
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_aus_v_8_2
  - enterprise_linux_appstream_aus_v_8_4
  - enterprise_linux_appstream_eus_extension_v_8_4
  - enterprise_linux_appstream_aus_v_8_6
  - enterprise_linux_appstream_e4s_v_8_6
  - enterprise_linux_appstream_tus_v_8_6
  - enterprise_linux_appstream_e4s_v_8_8
  - enterprise_linux_appstream_tus_v_8_8
  - enterprise_linux_appstream_e4s_v_9_0
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_eus_v_9_4
  - enterprise_linux_appstream_v_9
  - enterprise_linux_baseos_v_10
  - enterprise_linux_baseos_v_8
  - enterprise_linux_baseos_aus_v_8_2
  - enterprise_linux_baseos_aus_v_8_4
  - enterprise_linux_baseos_eus_extension_v_8_4
  - enterprise_linux_baseos_aus_v_8_6
  - enterprise_linux_baseos_e4s_v_8_6
  - enterprise_linux_baseos_tus_v_8_6
  - enterprise_linux_baseos_e4s_v_8_8
  - enterprise_linux_baseos_tus_v_8_8
  - enterprise_linux_baseos_e4s_v_9_0
  - enterprise_linux_baseos_e4s_v_9_2
  - enterprise_linux_baseos_eus_v_9_4
published: '2025-07-10'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:17:32.063'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-7425'
references:
  - url: 'https://access.redhat.com/errata/RHBA-2025:12345'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:12447'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:12450'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:13267'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:13308'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:13309'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:13310'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:13311'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:13312'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:13313'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:13314'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:13335'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:13464'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:13622'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14059'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14396'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14818'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14819'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14853'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14858'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15308'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15672'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15827'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15828'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:18219'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:21885'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:21913'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:0934'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:11503'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-7425'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2379274'
    label: secalert@redhat.com
  - url: 'https://gitlab.gnome.org/GNOME/libxslt/-/issues/140'
    label: secalert@redhat.com
  - url: 'http://seclists.org/fulldisclosure/2025/Aug/0'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Jul/30'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Jul/32'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Jul/35'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Jul/37'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2025/07/11/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2025/09/msg00035.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-032379.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-082556.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-265688.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-577017.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://gitlab.gnome.org/GNOME/libxslt/-/issues/140'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-7425.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-7425'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-7425'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
epss: 0.00358
epssPercentile: 0.29624
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-07-10T15:21:27.766014Z'
ingestedAt: '2026-06-29T13:24:34.392Z'
---

## Overview

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2025:13464** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS) · released 2025-08-07 · [advisory](https://access.redhat.com/errata/RHSA-2025:13464)
- **RHSA-2025:15308** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.12 · released 2025-09-11 · [advisory](https://access.redhat.com/errata/RHSA-2025:15308)
- **RHSA-2026:0934** · Red Hat · fixed in: 8Base-Openshift-Serverless-1.36 · released 2026-01-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:0934)
- **RHSA-2025:15672** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2025-09-18 · [advisory](https://access.redhat.com/errata/RHSA-2025:15672)
- **RHSA-2025:14853** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2025-09-04 · [advisory](https://access.redhat.com/errata/RHSA-2025:14853)
- **RHSA-2025:14396** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.15 · released 2025-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2025:14396)
- **RHSA-2025:14858** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2025-09-04 · [advisory](https://access.redhat.com/errata/RHSA-2025:14858)
- **RHSA-2025:14059** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.17 · released 2025-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2025:14059)
- **RHSA-2025:14818** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2025-09-04 · [advisory](https://access.redhat.com/errata/RHSA-2025:14818)
- **RHSA-2025:14819** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.19 · released 2025-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2025:14819)
- **RHSA-2025:15828** · Red Hat · fixed in: Red Hat Web Terminal 1.11 on RHEL 9 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15828)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 6, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat OpenShift Container Platform 4 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-7425.json)
