PT-2025-29100 · Libxslt+5 · Libxslt+5

Ivan Fratric

·

Published

2025-07-10

·

Updated

2026-05-08

·

CVE-2025-7424

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: libxslt (affected versions not specified)
Description: A type confusion issue exists in the libxslt library due to the reuse of the same memory field, psvi, for both stylesheet and input data during XML transformations. This can lead to application crashes, memory corruption, denial of service, or unexpected behavior.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-65367
AZL-65406
BDU:2025-11248
BIT-JAVA-2025-7424
BIT-JAVA-MIN-2025-7424
BIT-JRE-2025-7424
CVE-2025-7424
DLA-4309-1
DSA-5979-1
DSA-5979-2
ECHO-C801-94C9-AC17
MGASA-2025-0269
OESA-2025-1931
OPENSUSE-SU-2025:15364-1
RHSA-2026:11015
SUSE-SU-2025:20556-1
SUSE-SU-2025:20661-1
USN-7945-1

Affected Products

Debian
Linuxmint
Apple Macos
Red Os
Ubuntu
Libxslt