PT-2025-29101 · Libxslt+10 · Libxslt+10

Sergei Glazunov

·

Published

2025-04-15

·

Updated

2026-05-08

·

CVE-2025-7425

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions libxml2 and libxslt versions prior to 2.12.7+dfsg+really2.9.14-0.4ubuntu0.4 libxslt versions 1.1.35-1.2+deb13u1 libxml2 versions prior to 2.9.14+dfsg-1.3~deb12u4 libxml2 versions prior to 2.12.7+dfsg+really2.9.14-2.1+deb13u1 SLE 15 SP7
Description A heap use-after-free vulnerability exists in libxml2 and libxslt due to improper handling of attribute types, specifically the atype flags. This flaw occurs when processing certain XSLT operations, leading to memory corruption. Exploitation can result in crashes or potentially allow an attacker to execute arbitrary code. The vulnerability impacts various systems, including AWS Lambda base images and Oracle Linux.
Recommendations Update libxml2 to version 2.12.7+dfsg+really2.9.14-0.4ubuntu0.4 or later. Update libxslt to a version later than 1.1.35-1.2+deb13u1. Update libxml2 to version 2.9.14+dfsg-1.3~deb12u4 or later. Update libxml2 to version 2.12.7+dfsg+really2.9.14-2.1+deb13u1 or later. Apply the security patches for SLE 15 SP7.

Exploit

Fix

RCE

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2025:12447
ALSA-2025:12450
AZL-65409
AZL-73183
AZL-75182
BDU:2026-04327
BIT-JAVA-2025-7425
BIT-JAVA-MIN-2025-7425
BIT-JRE-2025-7425
CESA-2025_12450
CVE-2025-7425
DLA-4319-1
DSA-5990-1
ECHO-511D-3254-A5D5
INFSA-2025_12447
INFSA-2025_12450
MGASA-2025-0269
OPENSUSE-SU-2025:15363-1
RHSA-2025:12447
RHSA-2025:12450
RHSA-2025:13308
RHSA-2025:13309
RHSA-2025:13310
RHSA-2025:13311
RHSA-2025:13312
RHSA-2025:13313
RHSA-2025:13314
RHSA-2025:13464
RHSA-2025_12447
RHSA-2025_12450
RHSA-2026:11503
SUSE-SU-2025:02547-1
SUSE-SU-2025:02617-1
SUSE-SU-2025:02620-1
SUSE-SU-2025:02621-1
SUSE-SU-2025:02758-1
SUSE-SU-2025:20564-1
SUSE-SU-2025:20607-1
SUSE-SU-2025_02547-1
SUSE-SU-2025_02617-1
SUSE-SU-2025_02620-1
SUSE-SU-2025_02621-1
SUSE-SU-2025_02758-1
USN-7852-1
USN-7852-2
USN-7896-1

Affected Products

Almalinux
Centos
Debian
Java Platform
Linuxmint
Apple Macos
Red Hat
Rocky Linux
Suse
Ubuntu
Libxslt