CVE-2025-9714

Red Hat Security Advisory: Red Hat AI Inference Server 3.2.2 (CUDA)

mediumEPSS 0.1%

Description

A flaw was found in libxstl/libxml2. The 'exsltDynMapFunction' function in libexslt/dynamic.c does not contain a recursion depth check, which may cause an infinite loop via a specially crafted XSLT document while handling 'dyn:map()', leading to stack exhaustion and a local denial of service.

Metrics

Severity
medium
no public PoC known
6.2
Source: nvd-v3
4.9 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
0.1 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-02-27 14:54 UTC
CWE-674

Weakness classes (CWE)

  • CWE-674Class

    Uncontrolled Recursion

    The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

    cwe.mitre.org →

Affected operating systems

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    ubuntu / gdaltrusty

  • linux

    ubuntu / gdalxenial

  • linux

    ubuntu / golang-go.cryptobionic

  • linux

    ubuntu / golang-go.cryptofocal

  • linux

    ubuntu / golang-go.cryptojammy

  • linux

    ubuntu / golang-go.cryptonoble

  • linux

    ubuntu / golang-go.cryptoquesting

  • linux

    ubuntu / golang-go.cryptoxenial

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • aiohttp

    aiohttp3.13.3

  • anyscale

    ray2.52.0

  • bitnami

    golang1.24.0

  • bitnami

    sqlite

  • Dell

    Secure Connect GatewayAppliance 5.32.00.18

  • go

    github.com/opencontainers/runc1.0.0-rc3

  • go

    github.com/opencontainers/runc1.3.0-rc.1

  • go

    github.com/opencontainers/runc1.4.0-rc.1

  • go

    github.com/sigstore/fulcio

  • go

    golang.org/x/oauth2

  • google

    protobuf33.4

  • IBM

    AIX7.2

  • IBM

    AIX7.3

  • IBM

    Concert< 3.0.0

    fixed in 3.0.0

  • IBM

    DevOps Code ClearCase10.0.1.05

  • IBM

    DevOps Code ClearCase11.0.0.05

  • IBM

    DevOps Code ClearCase9.1.0.10

  • IBM

    MQContainer

  • IBM

    MQOperator

  • IBM

    TXSeriesfor multiplatforms

  • IBM

    VIOS3.1

  • IBM

    VIOS4.1

  • IGEL

    OS11.11.100

  • IGEL

    OS12.7.4

References & sources

Linked CVEs

Show 15 more CVEs
IDCVE-2025-9714