We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
Reserved 2025-07-10 | Published 2025-07-10 | Updated 2025-07-10 | Assigner redhat2025-07-10: | Reported to Red Hat. |
2025-07-10: | Made public. |
Red Hat would like to thank Sergei Glazunov (Google Project Zero) for reporting this issue.
access.redhat.com/security/cve/CVE-2025-7425
bugzilla.redhat.com/show_bug.cgi?id=2379274 (RHBZ#2379274)
gitlab.gnome.org/GNOME/libxslt/-/issues/140
Support options