Use-after-free in libxslt - CVE-2025-7425
Published: July 31, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the xsltSetSourceNodeFlags() function. A remote attacker can pass specially crafted XML input to the application, trigger memory corruption and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
SUSE Linux Enterprise Server 15 SP4
Debian Linux
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP3
SUSE Manager Server 4.3
SUSE Manager Retail Branch Server 4.3
SUSE Manager Proxy 4.3
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
visionOS
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Anolis OS
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
watchOS
Ubuntu
macOS
Basesystem Module
Python 3 Module
openSUSE Leap
tvOS
iPadOS
Apple iOS
IBM Observability with Instana
Netcool Operations Insight
Tenable Nessus
IBM Cloud Pak for Business Automation
Oracle Communications Cloud Native Core Certificate Management
OpenShift File Integrity Operator
OpenShift Compliance Operator
Guardium Data Security Center (GDSC)
IBM Security Verify Directory
Business Automation Insights
IBM Edge Application Manager
Nessus Network Monitor
Red Hat OpenShift Container Platform
IBM Qradar SIEM
Oracle Java SE
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libxml2 (Ubuntu package)
libxml2 (Red Hat package)
libxml2-static
libxml2
libxml2-devel
libxml2-python
libxml2-2
libxml2-2-debuginfo-32bit
libxml2-tools
libxml2-2-debuginfo
python-libxml2
libxml2-tools-debuginfo
python-libxml2-debuginfo
python-libxml2-debugsource
libxml2-debugsource
libxml2-doc
libxml2-2-32bit
python3-libxml2
python-libxml2-python-debugsource
python3-libxml2-python
python3-libxml2-python-debuginfo
libxml2-2-32bit-debuginfo
libxml2 (Debian package)
libxml2-2-64bit-debuginfo
python3-libxml2-debuginfo
libxml2-devel-64bit
libxml2-2-64bit
python311-libxml2
python311-libxml2-debuginfo
libxml2-devel-32bit
libxml2-python-debugsource
IBM API Connect
Apple Safari
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
Red Hat Ceph Storage
How to mitigate CVE-2025-7425
Netcool Operations Insight - update to 1.6.15
visionOS - update to 2.6
Guardium Data Security Center (GDSC) - update to 3.8.5
Nessus Network Monitor - update to 6.5.3
IBM Qradar SIEM - update to 7.5.0 Update Pack 13 IF01
Tenable Nessus - addressed in versions 10.8.0, 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5, 10.8.6, 10.9.6, 10.11.1
IBM Security Verify Directory - update to 10.0.4.0.1
IBM API Connect - update to 10.0.8.5
watchOS - update to 11.6
macOS - update to 15.6 24G84
Apple Safari - update to 18.6
tvOS - update to 18.6
iPadOS - update to 18.6 22G86
Apple iOS - update to 18.6 22G86
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
Red Hat OpenShift Serverless - update to 1
OpenShift File Integrity Operator - update to 1.3.7
OpenShift Compliance Operator - update to 1.8.0
Multicluster Engine for Kubernetes - update to 2.6.8
libxml2 (Ubuntu package) - addressed in versions 2.9.1+dfsg1-3ubuntu4.13+esm10, 2.9.3+dfsg1-1ubuntu0.7+esm11, 2.9.4+dfsg1-6.1ubuntu1.9+esm6, 2.9.10+dfsg-5ubuntu0.20.04.10+esm3, 2.9.13+dfsg-1ubuntu0.10, 2.9.14+dfsg-1.3ubuntu3.6, 2.12.7+dfsg+really2.9.14-0.4ubuntu0.4
libxml2 (Red Hat package) - addressed in versions 2.9.1-6.el7_9.12, 2.9.7-9.el8_2.4, 2.9.7-9.el8_4.7, 2.9.7-13.el8_6.11, 2.9.7-16.el8_8.10, 2.9.7-21.el8_10.2, 2.9.13-1.el9_0.6, 2.9.13-3.el9_2.8, 2.9.13-11.el9_6
libxml2-static - addressed in versions 2.9.1-6.0.2, 2.11.5-13
libxml2 - addressed in versions 2.9.1-6.0.2, 2.9.7-21.0.1, 2.11.5-13
libxml2-devel - addressed in versions 2.9.1-6.0.2, 2.9.7-21.0.1, 2.11.5-13
libxml2-python - update to 2.9.1-6.0.2
libxml2-2 - addressed in versions 2.9.4-46.90.1, 2.9.7-150000.3.85.1, 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1, 2.12.10-150700.4.6.1
libxml2-2-debuginfo-32bit - update to 2.9.4-46.90.1
libxml2-tools - addressed in versions 2.9.4-46.90.1, 2.9.7-150000.3.85.1, 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1, 2.12.10-150700.4.6.1
libxml2-2-debuginfo - addressed in versions 2.9.4-46.90.1, 2.9.7-150000.3.85.1, 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1, 2.12.10-150700.4.6.1
libxml2-devel - addressed in versions 2.9.4-46.90.1, 2.9.7-150000.3.85.1, 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1, 2.12.10-150700.4.6.1
python-libxml2 - update to 2.9.4-46.90.1
libxml2-tools-debuginfo - addressed in versions 2.9.4-46.90.1, 2.9.7-150000.3.85.1, 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1, 2.12.10-150700.4.6.1
python-libxml2-debuginfo - update to 2.9.4-46.90.1
python-libxml2-debugsource - update to 2.9.4-46.90.1
libxml2-debugsource - addressed in versions 2.9.4-46.90.1, 2.9.7-150000.3.85.1, 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1, 2.12.10-150700.4.6.1
libxml2-doc - addressed in versions 2.9.4-46.90.1, 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1
libxml2-2-32bit - addressed in versions 2.9.4-46.90.1, 2.9.7-150000.3.85.1, 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1, 2.12.10-150700.4.6.1
python3-libxml2 - addressed in versions 2.9.7-21.0.1, 2.11.5-13
python-libxml2-python-debugsource - update to 2.9.7-150000.3.85.1
python3-libxml2-python - update to 2.9.7-150000.3.85.1
python3-libxml2-python-debuginfo - update to 2.9.7-150000.3.85.1
libxml2-2-32bit-debuginfo - addressed in versions 2.9.7-150000.3.85.1, 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1, 2.12.10-150700.4.6.1
libxml2 (Debian package) - addressed in versions 2.9.14+dfsg-1.3~deb12u4, 2.12.7+dfsg+really2.9.14-2.1+deb13u1
libxml2-2-64bit-debuginfo - addressed in versions 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1
python3-libxml2 - addressed in versions 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1, 2.12.10-150700.4.6.1
python3-libxml2-debuginfo - addressed in versions 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1, 2.12.10-150700.4.6.1
libxml2-devel-64bit - addressed in versions 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1
libxml2-2-64bit - addressed in versions 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1
python311-libxml2 - addressed in versions 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1, 2.12.10-150700.4.6.1
python311-libxml2-debuginfo - addressed in versions 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1, 2.12.10-150700.4.6.1
libxml2-devel-32bit - addressed in versions 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1
libxml2-python-debugsource - addressed in versions 2.9.14-150400.5.47.1, 2.10.3-150500.5.32.1, 2.12.10-150700.4.6.1
libxml2-doc - update to 2.11.5-13
Red Hat OpenShift Container Platform - addressed in versions 4.12.80, 4.13.60, 4.14.55, 4.14.56, 4.15.57, 4.16.47, 4.17.38, 4.18.23, 4.19.10
Red Hat Ceph Storage - update to 7.1
External References
Related Security Bulletins
- Use-after-free in libxslt
- SUSE update for libxml2
- Multiple vulnerabilities in macOS Sequoia
- Multiple vulnerabilities in Apple iOS and iPadOS
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple visionOS
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple Safari
- Red Hat Enterprise Linux 9 update for libxml2
- Red Hat Enterprise Linux 8 update for libxml2
- Anolis OS update for libxml2
- SUSE update for libxml2
- SUSE update for libxml2
- SUSE update for libxml2
- Red Hat Enterprise Linux 8 update for libxml2
- Red Hat Enterprise Linux 9 update for libxml2
- Red Hat Enterprise Linux 8 update for libxml2
- Red Hat Enterprise Linux 8 update for libxml2
- Red Hat Enterprise Linux 8 update for libxml2
- Red Hat Enterprise Linux 9 update for libxml2
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for libxml2
- Multiple vulnerabilities in IBM Security Verify Directory
- SUSE update for libxml2
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.6
- Multiple vulnerabilities in Red Hat Ceph Storage 7
- Multiple vulnerabilities in Red Hat Ceph Storage 7
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Debian update for libxml2
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Certificate Management
- Ubuntu update for libxml2
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in OpenShift Compliance Operator
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in OpenShift File Integrity Operator
- Ubuntu update for libxml2
- Ubuntu update for libxml2
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in Tenable Nessus
- Anolis OS update for libxml2
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in Oracle Java SE
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Tenable Network Monitor update for third-party components
- Anolis OS update for libxml2
- Anolis OS update for libxml2