CVE-2025-7425: Use After Free in GNOME libxml2
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
AI Analysis
Technical Summary
The vulnerability in libxslt arises from modification of the attribute type (atype) and flags, which corrupts internal memory management. When XSLT functions like key() produce tree fragments, this corruption prevents proper cleanup of ID attributes, resulting in use-after-free conditions. This can lead to crashes or heap corruption. Red Hat advisories RHBA-2025:12345 and RHSA-2025:12447 confirm the issue and provide patches for affected Red Hat Enterprise Linux 9 and 10 versions.
Potential Impact
Successful exploitation can cause heap corruption or application crashes due to use-after-free conditions in libxslt processing. The CVSS 3.1 score is 7.8 (High), indicating significant impact on integrity and availability but requiring local access with high attack complexity and no privileges.
Mitigation Recommendations
Official patches are available from Red Hat for affected Red Hat Enterprise Linux 9 and 10 versions. Users should apply the updates as described in Red Hat advisories RHBA-2025:12345 and RHSA-2025:12447. No additional mitigation is required beyond applying these official fixes.
CVE-2025-7425: Use After Free in GNOME libxml2
Description
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
CVSS v3.1
Score 7.8high
Affected software
GNOME
libxml2
Red Hat
Red Hat Enterprise Linux 10
Red Hat
Red Hat Enterprise Linux 10
Red Hat
Red Hat Enterprise Linux 7 Extended Lifecycle Support
Red Hat
Red Hat Enterprise Linux 8
Red Hat
Red Hat Enterprise Linux 8.2 Advanced Update Support
Red Hat
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red Hat
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red Hat
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
Red Hat
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
Red Hat
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Red Hat
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red Hat
Red Hat Enterprise Linux 9
Red Hat
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
Red Hat
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Red Hat
Red Hat Enterprise Linux 9.4 Extended Update Support
Red Hat
Red Hat OpenShift Container Platform 4.12
Red Hat
Red Hat OpenShift Container Platform 4.13
Red Hat
Red Hat OpenShift Container Platform 4.14
Red Hat
Red Hat OpenShift Container Platform 4.15
Red Hat
Red Hat OpenShift Container Platform 4.16
Red Hat
Red Hat OpenShift Container Platform 4.17
Red Hat
Red Hat OpenShift Container Platform 4.18
Red Hat
Red Hat OpenShift Container Platform 4.19
Red Hat
Red Hat Web Terminal 1.11 on RHEL 9
Red Hat
Red Hat Web Terminal 1.11 on RHEL 9
Red Hat
Red Hat Web Terminal 1.12 on RHEL 9
Red Hat
RHOSS-1.36-RHEL-8
Red Hat
RHOSS-1.36-RHEL-8
Red Hat
RHOSS-1.36-RHEL-8
Red Hat
RHOSS-1.36-RHEL-8
Red Hat
RHOSS-1.36-RHEL-8
Red Hat
RHOSS-1.36-RHEL-8
Red Hat
RHOSS-1.36-RHEL-8
Red Hat
cert-manager operator for Red Hat OpenShift 1.16
Red Hat
Compliance Operator 1
Red Hat
OpenShift File Integrity Operator - FIO 1
Red Hat
Red Hat Discovery 2
Red Hat
Red Hat Hardened Images
Red Hat
Red Hat Insights proxy 1.5
Red Hat
Red Hat OpenShift distributed tracing 3.5.3
Red Hat
Red Hat OpenShift distributed tracing 3.5.3
Red Hat
Red Hat OpenShift distributed tracing 3.5.3
Red Hat
Red Hat OpenShift distributed tracing 3.5.3
Red Hat
Red Hat OpenShift distributed tracing 3.5.3
Red Hat
Red Hat OpenShift distributed tracing 3.5.3
Red Hat
Red Hat OpenShift distributed tracing 3.5.3
Red Hat
Red Hat OpenShift distributed tracing 3.5.3
Red Hat
Red Hat Enterprise Linux 6
Red Hat
Red Hat OpenShift Container Platform 4
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in libxslt arises from modification of the attribute type (atype) and flags, which corrupts internal memory management. When XSLT functions like key() produce tree fragments, this corruption prevents proper cleanup of ID attributes, resulting in use-after-free conditions. This can lead to crashes or heap corruption. Red Hat advisories RHBA-2025:12345 and RHSA-2025:12447 confirm the issue and provide patches for affected Red Hat Enterprise Linux 9 and 10 versions.
Potential Impact
Successful exploitation can cause heap corruption or application crashes due to use-after-free conditions in libxslt processing. The CVSS 3.1 score is 7.8 (High), indicating significant impact on integrity and availability but requiring local access with high attack complexity and no privileges.
Mitigation Recommendations
Official patches are available from Red Hat for affected Red Hat Enterprise Linux 9 and 10 versions. Users should apply the updates as described in Red Hat advisories RHBA-2025:12345 and RHSA-2025:12447. No additional mitigation is required beyond applying these official fixes.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- redhat
- Date Reserved
- 2025-07-10T08:44:06.287Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/errata/RHBA-2025:12345","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:12447","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:12450","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:13267","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:13308","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:13309","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:13310","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:13311","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:13312","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:13313","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:13314","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:13335","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:13464","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:13622","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:14059","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:14396","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:14818","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:14819","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:14853","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:14858","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:15308","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:15672","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:15827","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:15828","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:18219","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:21885","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:21913","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:0934","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2025-7425","vendor":"Red Hat"}]
Threat ID: 686fc7a4a83201eaaca7ffbb
Added to database: 07/10/2025, 14:01:08 UTC
Last enriched: 08/14/2026, 13:18:21 UTC
Last updated: 09/10/2026, 19:46:21 UTC
Views: 735
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.