CVE-2025-7425

HIGH7.8EPSS 0.19%

Libxslt: libxml2: heap use-after-free in libxslt caused by atype corruption in xmlattrptr

發布日:2025/7/10修改日:2026/5/13

描述

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.

受影響套件(5)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.8CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H

參考連結(45)