CVE-2025-7424

A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt memory. In some cases, it may lead to denial of service or unexpected behavior.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2025-7424 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2379228 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:xmlsoft:libxslt:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

27 Aug 2025, 18:00

Type Values Removed Values Added
CPE cpe:2.3:a:xmlsoft:libxslt:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
References () https://access.redhat.com/security/cve/CVE-2025-7424 - () https://access.redhat.com/security/cve/CVE-2025-7424 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2379228 - () https://bugzilla.redhat.com/show_bug.cgi?id=2379228 - Issue Tracking, Third Party Advisory
First Time Redhat
Redhat enterprise Linux
Xmlsoft
Redhat openshift Container Platform
Xmlsoft libxslt

15 Jul 2025, 13:24

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-10 14:15

Updated : 2025-08-27 18:00


NVD link : CVE-2025-7424

Mitre link : CVE-2025-7424

CVE.ORG link : CVE-2025-7424


JSON object : View

Products Affected

xmlsoft

  • libxslt

redhat

  • enterprise_linux
  • openshift_container_platform
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')