Memory Management Vulnerability in libxslt by Red Hat
CVE-2025-7425
Key Information:
What is CVE-2025-7425?
A memory management flaw in libxslt allows improper handling of the atype attribute flags, leading to potential memory corruption. When the key() function in XSLT processes certain tree fragments, it fails to clean up ID attributes properly, which may result in the system accessing freed memory. This could cause application crashes or may be exploited by attackers to trigger heap corruption, posing significant risks to application stability and security.
Affected Version(s)
cert-manager operator for Red Hat OpenShift 1.16 sha256:330e8b5ab4841a21f8f5f23cc7fb192197872f11639b12bf4b1e70831f636323
Compliance Operator 1 sha256:6ab41bd207ae7e33f29adc87e208366472654bb5fb9b1854234cc5674ecc169e
Compliance Operator 1 sha256:09f37fa618a4e02460b28b1097148573b395354300db5f917ed155ab7968b779
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved