CVE-2025-7425

Red Hat Security Advisory: updated web-terminal/tooling container image

Description

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.

Metrics

Severity
high
no public PoC known
7.8
Source: nvd-v3
27.7 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2025-09-15 15:14 UTC
CWE-416

Weakness classes (CWE)

  • CWE-416Variant

    Use After Free

    The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-08 16:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/7xxx/CVE-2025-7425.json">CVE-2025-7425</a>
  2. CVE Modified2026-09-07 20:16 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/7xxx/CVE-2025-7425.json">CVE-2025-7425</a>
  3. CVE Modified2026-09-06 04:18 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/7xxx/CVE-2025-7425.json">CVE-2025-7425</a>
  4. CVE Modified2026-09-05 16:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/7xxx/CVE-2025-7425.json">CVE-2025-7425</a>
  5. CVE Modified2026-08-31 17:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/7xxx/CVE-2025-7425.json">CVE-2025-7425</a>
    • Reference: https://access.redhat.com/errata/RHBA-2025:12345
    • Reference: https://access.redhat.com/errata/RHSA-2025:12447
    • Reference: https://access.redhat.com/errata/RHSA-2025:12450

Affected operating systems

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • bitnami

    git

  • bitnami

    java-min1.9.0

  • bitnami

    sqlite

  • go

    golang.org/x/net

  • go

    stdlib1.22.0-0

  • libarchive

    libarchive3.8.0

  • Oracle

    Fusion Middleware12.2.1.4.0

  • Oracle

    Fusion Middleware14.1.1.0.0

  • Oracle

    Fusion Middleware14.1.2.0.0

  • Oracle

    Fusion Middleware14.1.2.1.0

  • Oracle

    Fusion Middleware15.1.1.0.0

  • Oracle

    Fusion Middleware8.5.7

  • Oracle

    Fusion Middleware8.5.8

  • redhat

    openshift_container_platform

References & sources

Linked CVEs

IDCVE-2025-7425