CVE-2025-7425
HIGH7.8EPSS 0.19%libxml2 - security update
Published: 7/10/2025Modified: 8/29/2025
Also known as:DSA-5990-1
Description
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
Affected packages (5)
- Bitnami/javafrom 0, < 1.8.0, >= 1.9.0, < 8.0.481
- Bitnami/java-minfrom 0, < 1.8.0, >= 1.9.0, < 8.0.481
- Bitnami/jrefrom 0, < 1.8.0, >= 1.9.0, < 8.0.481
- Debian/libxml2from 0, < 2.9.14+dfsg-1.3~deb12u4
- Debian/libxsltfrom 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.8 | CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H |
References (45)
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2025-7425
- WEBhttps://access.redhat.com/errata/RHBA-2025:12345
- WEBhttps://access.redhat.com/errata/RHSA-2025:12447
- WEBhttps://access.redhat.com/errata/RHSA-2025:12450
- WEBhttps://access.redhat.com/errata/RHSA-2025:13267
- WEBhttps://access.redhat.com/errata/RHSA-2025:13308
- WEBhttps://access.redhat.com/errata/RHSA-2025:13309
- WEBhttps://access.redhat.com/errata/RHSA-2025:13310
- WEBhttps://access.redhat.com/errata/RHSA-2025:13311
- WEBhttps://access.redhat.com/errata/RHSA-2025:13312
- WEBhttps://access.redhat.com/errata/RHSA-2025:13313
- WEBhttps://access.redhat.com/errata/RHSA-2025:13314
- WEBhttps://access.redhat.com/errata/RHSA-2025:13335
- WEBhttps://access.redhat.com/errata/RHSA-2025:13464
- WEBhttps://access.redhat.com/errata/RHSA-2025:13622
- WEBhttps://access.redhat.com/errata/RHSA-2025:14059
- WEBhttps://access.redhat.com/errata/RHSA-2025:14396
- WEBhttps://access.redhat.com/errata/RHSA-2025:14818
- WEBhttps://access.redhat.com/errata/RHSA-2025:14819
- WEBhttps://access.redhat.com/errata/RHSA-2025:14853
- WEBhttps://access.redhat.com/errata/RHSA-2025:14858
- WEBhttps://access.redhat.com/errata/RHSA-2025:15308
- WEBhttps://access.redhat.com/errata/RHSA-2025:15672
- WEBhttps://access.redhat.com/errata/RHSA-2025:15827
- WEBhttps://access.redhat.com/errata/RHSA-2025:15828
- WEBhttps://access.redhat.com/errata/RHSA-2025:18219
- WEBhttps://access.redhat.com/errata/RHSA-2025:21885
- WEBhttps://access.redhat.com/errata/RHSA-2025:21913
- WEBhttps://access.redhat.com/errata/RHSA-2026:0934
- WEBhttps://access.redhat.com/errata/RHSA-2026:11503
- WEBhttps://access.redhat.com/security/cve/CVE-2025-7425
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=2379274
- WEBhttps://cert-portal.siemens.com/productcert/html/ssa-032379.html
- WEBhttps://cert-portal.siemens.com/productcert/html/ssa-082556.html
- WEBhttps://cert-portal.siemens.com/productcert/html/ssa-265688.html
- WEBhttps://cert-portal.siemens.com/productcert/html/ssa-577017.html
- WEBhttp://seclists.org/fulldisclosure/2025/Aug/0
- WEBhttp://seclists.org/fulldisclosure/2025/Jul/30
- WEBhttp://seclists.org/fulldisclosure/2025/Jul/32
- WEBhttp://seclists.org/fulldisclosure/2025/Jul/35
- WEBhttp://seclists.org/fulldisclosure/2025/Jul/37
- WEBhttps://gitlab.gnome.org/GNOME/libxslt/-/issues/140
- WEBhttps://lists.debian.org/debian-lts-announce/2025/09/msg00035.html
- WEBhttps://nvd.nist.gov/vuln/detail/CVE-2025-7425
- WEBhttp://www.openwall.com/lists/oss-security/2025/07/11/2