CVE-2025-7425
published 2025-07-10CVE-2025-7425: A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as…
PriorityP342high7.8CVSS 3.1
AVLACHPRNUINSCCNIHAH
EPSS
0.34%
26.0th percentile
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.6_and_ipados | — | — |
| apple | macos_sequoia | — | — |
| apple | safari | — | — |
| apple | tvos | — | — |
| apple | visionos | — | — |
| apple | watchos | — | — |
| debian | libxslt | — | — |
| gnome | libxml2 | < 2.15.2 | 2.15.2 |
| msrc | azl3_libxml2_2.11.5-7_on_azure_linux_3.0 | — | — |
| msrc | azl3_libxml2_2.11.5-8_on_azure_linux_3.0 | — | — |
| msrc | azl3_libxslt_1.1.43-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_libxslt_1.1.43-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libxslt_1.1.34-10_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libxslt_1.1.34-8_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libxslt_1.1.34-9_on_cbl_mariner_2.0 | — | — |
| xmlsoft | libxml2 | >= 0 < 2.9.1+dfsg1-3ubuntu4.13+esm10 | 2.9.1+dfsg1-3ubuntu4.13+esm10 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
vendor_msrc7.3HIGH
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Java SE Risk Matrix: JavaFX (libxslt) — CVE-2025-7425
vendor_oracle·2026-01-15·CVSS 7.5
CVE-2025-7425 [HIGH] Oracle Oracle Java SE Risk Matrix: JavaFX (libxslt) — CVE-2025-7425
Oracle Oracle Java SE Risk Matrix: JavaFX (libxslt) vulnerability
CVE: CVE-2025-7425
CVSS: 7.5
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Ubuntu
libxml2 vulnerability
vendor_ubuntu·2025-11-27
CVE-2025-7425 libxml2 vulnerability
Title: libxml2 vulnerability
Summary: libxml2 could be made to crash or run programs if it opened a specially crafted file.
USN-7582-1 fixed a vulnerability in libxml2. This update provides the
corresponding fix for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that libxslt, used by libxml2, incorrectly handled
certain attributes. An attacker could use this issue to cause a crash,
resulting in a denial of service, or possibly execute arbitrary code. This
update adds a fix to libxml2 to mitigate the libxslt vulnerability.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2025-11-27·CVSS 5.6
CVE-2025-7425 [MEDIUM] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: Several security issues were fixed in libxml2.
It was discovered that the libxml2 Python bindings incorrectly handled
certain return values. An attacker could possibly use this issue to cause
libxml2 to crash, resulting in a denial of service. (CVE-2025-32414)
It was discovered that libxml2 incorrectly handled certain memory
operations. A remote attacker could possibly use this issue to cause
libxml2 to crash, resulting in a denial of service. (CVE-2025-32415)
It was discovered that libxslt, used by libxml2, incorrectly handled
certain attributes. An attacker could use this issue to cause a crash,
resulting in a denial of service, or possibly execute arbitrary code. This
update adds a fix to libxml2 to mitigate the libxslt vulnerability.
(CVE-202
Ubuntu
libxml2 vulnerability
vendor_ubuntu·2025-10-30
CVE-2025-7425 libxml2 vulnerability
Title: libxml2 vulnerability
Summary: libxml2 could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that libxslt, used by libxml2, incorrectly handled
certain attributes. An attacker could use this issue to cause a crash,
resulting in a denial of service, or possibly execute arbitrary code. This
update adds a fix to libxml2 to mitigate the libxslt vulnerability.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (libxml2) — CVE-2025-7425
vendor_oracle·2025-10-15·CVSS 7.8
CVE-2025-7425 [HIGH] Oracle Oracle Communications Risk Matrix: Configuration (libxml2) — CVE-2025-7425
Oracle Oracle Communications Risk Matrix: Configuration (libxml2) vulnerability
CVE: CVE-2025-7425
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2025 (OCT 2025)
Apple
CVE-2025-7425: Safari 18.6
vendor_apple·2025-07-30·CVSS 7.8
CVE-2025-7425 [HIGH] CVE-2025-7425: Safari 18.6
Apple Security Update: About the security content of Safari 18.6
Product: Safari
Version: 18.6
CVE: CVE-2025-7425
Component: Safari 18.6
Impact: Processing a file may lead to memory corruption
Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
Apple
CVE-2025-7425: macOS Sequoia 15.6
vendor_apple·2025-07-29·CVSS 7.8
CVE-2025-7425 [HIGH] CVE-2025-7425: macOS Sequoia 15.6
Apple Security Update: About the security content of macOS Sequoia 15.6
Product: macOS Sequoia
Version: 15.6
CVE: CVE-2025-7425
Component: Kernel
Impact: An app may be able to cause unexpected system termination
Description: A double free issue was addressed with improved memory management.
Apple
CVE-2025-7425: tvOS 18.6
vendor_apple·2025-07-29·CVSS 7.8
CVE-2025-7425 [HIGH] CVE-2025-7425: tvOS 18.6
Apple Security Update: About the security content of tvOS 18.6
Product: tvOS
Version: 18.6
CVE: CVE-2025-7425
Component: Kernel
Impact: An app may be able to cause unexpected system termination
Description: A double free issue was addressed with improved memory management.
Apple
CVE-2025-7425: watchOS 11.6
vendor_apple·2025-07-29·CVSS 7.8
CVE-2025-7425 [HIGH] CVE-2025-7425: watchOS 11.6
Apple Security Update: About the security content of watchOS 11.6
Product: watchOS
Version: 11.6
CVE: CVE-2025-7425
Component: Kernel
Impact: An app may be able to cause unexpected system termination
Description: A double free issue was addressed with improved memory management.
Apple
CVE-2025-7425: iOS 18.6 and iPadOS 18.6
vendor_apple·2025-07-29·CVSS 7.8
CVE-2025-7425 [HIGH] CVE-2025-7425: iOS 18.6 and iPadOS 18.6
Apple Security Update: About the security content of iOS 18.6 and iPadOS 18.6
Product: iOS 18.6 and iPadOS
Version: 18.6
CVE: CVE-2025-7425
Component: Kernel
Impact: An app may be able to cause unexpected system termination
Description: A double free issue was addressed with improved memory management.
Apple
CVE-2025-7425: visionOS 2.6
vendor_apple·2025-07-29·CVSS 7.8
CVE-2025-7425 [HIGH] CVE-2025-7425: visionOS 2.6
Apple Security Update: About the security content of visionOS 2.6
Product: visionOS
Version: 2.6
CVE: CVE-2025-7425
Component: Kernel
Impact: An app may be able to cause unexpected system termination
Description: A double free issue was addressed with improved memory management.
Red Hat
libxslt: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr
vendor_redhat·2025-07-10·CVSS 7.8
CVE-2025-7425 [HIGH] CWE-416 libxslt: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr
libxslt: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or
Microsoft
Libxslt: heap use-after-free in libxslt caused by atype corruption in xmlattrptr
vendor_msrc·2025-07-08·CVSS 7.3
CVE-2025-7425 [HIGH] CWE-416 Libxslt: heap use-after-free in libxslt caused by atype corruption in xmlattrptr
Libxslt: heap use-after-free in libxslt caused by atype corruption in xmlattrptr
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Release
Debian
CVE-2025-7425: libxslt - A flaw was found in libxslt where the attribute type, atype, flags are modified ...
vendor_debian·2025·CVSS 7.8
CVE-2025-7425 [HIGH] CVE-2025-7425: libxslt - A flaw was found in libxslt where the attribute type, atype, flags are modified ...
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
Scope: local
bookworm: resolved
bullseye: resolved
forky: open
sid: open
trixie: resolved
OSV
libxml2 vulnerabilities
osv·2025-11-27·CVSS 7.5
CVE-2025-32414 [HIGH] libxml2 vulnerabilities
libxml2 vulnerabilities
It was discovered that the libxml2 Python bindings incorrectly handled
certain return values. An attacker could possibly use this issue to cause
libxml2 to crash, resulting in a denial of service. (CVE-2025-32414)
It was discovered that libxml2 incorrectly handled certain memory
operations. A remote attacker could possibly use this issue to cause
libxml2 to crash, resulting in a denial of service. (CVE-2025-32415)
It was discovered that libxslt, used by libxml2, incorrectly handled
certain attributes. An attacker could use this issue to cause a crash,
resulting in a denial of service, or possibly execute arbitrary code. This
update adds a fix to libxml2 to mitigate the libxslt vulnerability.
(CVE-2025-7425)
GHSA
GHSA-8c4w-j52q-j4jq: A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management
ghsa_unreviewed·2025-07-10
CVE-2025-7425 [HIGH] CWE-416 GHSA-8c4w-j52q-j4jq: A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
OSV
CVE-2025-7425: A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management
osv·2025-07-10·CVSS 7.8
CVE-2025-7425 [HIGH] CVE-2025-7425: A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-7425 libxslt: libxml2: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr
bugzilla·2025-07-10·CVSS 7.8
CVE-2025-7425 [HIGH] CVE-2025-7425 libxslt: libxml2: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr
CVE-2025-7425 libxslt: libxml2: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr
Use-After-Free vulnerability in libxslt caused by unsafe manipulation of the atype field in attribute nodes. The flaw occurs when xsltSetSourceNodeFlags() sets extra flag bits on xmlAttrPtr->atype, a field later used by libxml2 to check whether an attribute is an XML ID. This corruption can cause libxml2 to skip cleanup steps like xmlRemoveID() during memory deallocation. As a result, ID table entries may point to freed memory, and later calls to xmlFreeID() will dereference these dangling pointers, triggering a use-after-free. This vulnerability is exploitable through crafted XSLT using the key() function and result tree fragments, and may result in denial-of-service or memory corrupti
Bugzilla
CVE-2025-7425 qt5-qtwebengine: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr [fedora-42]
bugzilla·2025-07-10·CVSS 7.8
CVE-2025-7425 [HIGH] CVE-2025-7425 qt5-qtwebengine: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr [fedora-42]
CVE-2025-7425 qt5-qtwebengine: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379274
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open
Bugzilla
CVE-2025-7425 mingw-libxslt: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr [fedora-42]
bugzilla·2025-07-10·CVSS 7.8
CVE-2025-7425 [HIGH] CVE-2025-7425 mingw-libxslt: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr [fedora-42]
CVE-2025-7425 mingw-libxslt: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379274
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open wi
Bugzilla
CVE-2025-7425 libxslt: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr [fedora-42]
bugzilla·2025-07-10·CVSS 7.8
CVE-2025-7425 [HIGH] CVE-2025-7425 libxslt: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr [fedora-42]
CVE-2025-7425 libxslt: Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2379274
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'
https://access.redhat.com/errata/RHBA-2025:12345https://access.redhat.com/errata/RHSA-2025:12447https://access.redhat.com/errata/RHSA-2025:12450https://access.redhat.com/errata/RHSA-2025:13267https://access.redhat.com/errata/RHSA-2025:13308https://access.redhat.com/errata/RHSA-2025:13309https://access.redhat.com/errata/RHSA-2025:13310https://access.redhat.com/errata/RHSA-2025:13311https://access.redhat.com/errata/RHSA-2025:13312https://access.redhat.com/errata/RHSA-2025:13313https://access.redhat.com/errata/RHSA-2025:13314https://access.redhat.com/errata/RHSA-2025:13335https://access.redhat.com/errata/RHSA-2025:13464https://access.redhat.com/errata/RHSA-2025:13622https://access.redhat.com/errata/RHSA-2025:14059https://access.redhat.com/errata/RHSA-2025:14396https://access.redhat.com/errata/RHSA-2025:14818https://access.redhat.com/errata/RHSA-2025:14819https://access.redhat.com/errata/RHSA-2025:14853https://access.redhat.com/errata/RHSA-2025:14858https://access.redhat.com/errata/RHSA-2025:15308https://access.redhat.com/errata/RHSA-2025:15672https://access.redhat.com/errata/RHSA-2025:15827https://access.redhat.com/errata/RHSA-2025:15828https://access.redhat.com/errata/RHSA-2025:18219https://access.redhat.com/errata/RHSA-2025:21885https://access.redhat.com/errata/RHSA-2025:21913https://access.redhat.com/errata/RHSA-2026:0934https://access.redhat.com/errata/RHSA-2026:11503https://access.redhat.com/security/cve/CVE-2025-7425https://bugzilla.redhat.com/show_bug.cgi?id=2379274https://gitlab.gnome.org/GNOME/libxslt/-/issues/140http://seclists.org/fulldisclosure/2025/Aug/0http://seclists.org/fulldisclosure/2025/Jul/30http://seclists.org/fulldisclosure/2025/Jul/32http://seclists.org/fulldisclosure/2025/Jul/35http://seclists.org/fulldisclosure/2025/Jul/37http://www.openwall.com/lists/oss-security/2025/07/11/2https://lists.debian.org/debian-lts-announce/2025/09/msg00035.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-032379.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-265688.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-577017.htmlhttps://gitlab.gnome.org/GNOME/libxslt/-/issues/140
2025-07-10
Published