CVE-2025-7424 – “Libxslt Type Confusion Memory Corruption Vulnerability”

The following table lists the changes that have been made to the
CVE-2025-7424 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jul. 10, 2025

    Action Type Old Value New Value
    Added Description A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt memory. In some cases, it may lead to denial of service or unexpected behavior.
    Added CVSS V3.1 AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
    Added CWE CWE-843
    Added Reference https://access.redhat.com/security/cve/CVE-2025-7424
    Added Reference https://bugzilla.redhat.com/show_bug.cgi?id=2379228
Share the Post:

Related Posts