Type confusion in libxslt - CVE-2025-7424

 

Type confusion in libxslt - CVE-2025-7424

Published: July 31, 2025


Vulnerability identifier: #VU113534
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-7424
CWE-ID: CWE-843
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a type confusion error in xmlNode.psvi. A remote attacker can pass specially crafted XML input to the application, trigger a type confusion error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

libxslt
Debian Linux
visionOS
watchOS
macOS
Ubuntu
tvOS
iPadOS
Apple iOS
openEuler
Anolis OS
Fedora
IBM Observability with Instana
Apple Safari
libxslt (Ubuntu package)
libxslt (Debian package)
libxslt-help
python3-libxslt
libxslt-devel
libxslt-debuginfo
libxslt
libxslt-debugsource
mingw-libxslt
libxslt-doc

How to mitigate CVE-2025-7424

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

IBM Observability with Instana - update to 1.0.307
visionOS - update to 2.6
watchOS - update to 11.6
macOS - addressed in versions 14.7.7 23H723, 15.6 24G84
tvOS - update to 18.6
Apple Safari - update to 18.6
iPadOS - addressed in versions 17.7.9, 18.6 22G86
Apple iOS - update to 18.6 22G86
libxslt (Ubuntu package) - addressed in versions 1.1.28-2ubuntu0.2+esm5, 1.1.28-2.1ubuntu0.3+esm4, 1.1.29-5ubuntu0.3+esm3, 1.1.34-4ubuntu0.20.04.3+esm2, 1.1.34-4ubuntu0.22.04.5, 1.1.39-0exp1ubuntu0.24.04.3, 1.1.39-0exp1ubuntu4.1
libxslt (Debian package) - addressed in versions 1.1.35-1+deb12u2, 1.1.35-1.2+deb13u1
libxslt-help - update to 1.1.39-5
python3-libxslt - update to 1.1.39-5
libxslt-devel - update to 1.1.39-5
libxslt-debuginfo - update to 1.1.39-5
libxslt - update to 1.1.39-5
libxslt-debugsource - update to 1.1.39-5
mingw-libxslt - addressed in versions 1.1.43-3.fc41, 1.1.43-3.fc42
libxslt - update to 1.1.43-4
libxslt-devel - update to 1.1.43-4
python3-libxslt - update to 1.1.43-4
libxslt-doc - update to 1.1.43-4

External References

Related Security Bulletins