CVE-2025-7424

A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt memory. In some cases, it may lead to denial of service or unexpected behavior.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xmlsoft:libxslt:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

04 Nov 2025, 22:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/07/11/2 -

03 Nov 2025, 20:19

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Aug/0 -
  • () http://seclists.org/fulldisclosure/2025/Jul/30 -
  • () http://seclists.org/fulldisclosure/2025/Jul/32 -
  • () http://seclists.org/fulldisclosure/2025/Jul/33 -
  • () http://seclists.org/fulldisclosure/2025/Jul/35 -
  • () http://seclists.org/fulldisclosure/2025/Jul/37 -

03 Nov 2025, 19:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/09/msg00024.html -

27 Aug 2025, 18:00

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2025-7424 - () https://access.redhat.com/security/cve/CVE-2025-7424 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2379228 - () https://bugzilla.redhat.com/show_bug.cgi?id=2379228 - Issue Tracking, Third Party Advisory
First Time Redhat
Redhat enterprise Linux
Xmlsoft
Redhat openshift Container Platform
Xmlsoft libxslt
CPE cpe:2.3:a:xmlsoft:libxslt:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*

15 Jul 2025, 13:24

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-10 14:15

Updated : 2025-11-04 22:16


NVD link : CVE-2025-7424

Mitre link : CVE-2025-7424

CVE.ORG link : CVE-2025-7424


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • openshift_container_platform

xmlsoft

  • libxslt
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')