CVE-2025-7424

A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt memory. In some cases, it may lead to denial of service or unexpected behavior.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xmlsoft:libxslt:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

04 Nov 2025, 22:16

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Aug/0 -
  • () http://seclists.org/fulldisclosure/2025/Jul/30 -
  • () http://seclists.org/fulldisclosure/2025/Jul/32 -
  • () http://seclists.org/fulldisclosure/2025/Jul/33 -
  • () http://seclists.org/fulldisclosure/2025/Jul/35 -
  • () http://seclists.org/fulldisclosure/2025/Jul/37 -
  • () http://www.openwall.com/lists/oss-security/2025/07/11/2 -
  • () https://lists.debian.org/debian-lts-announce/2025/09/msg00024.html -

Information

Published : 2025-07-10 14:15

Updated : 2025-11-04 22:16


NVD link : CVE-2025-7424

Mitre link : CVE-2025-7424

CVE.ORG link : CVE-2025-7424


JSON object : View

Products Affected

redhat

  • openshift_container_platform
  • enterprise_linux

xmlsoft

  • libxslt
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')