CVE-2025-7425: Gnome LIBXML2

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.

Affected products

  • Gnome LIBXML2: before 2.15.2 (fixed in 2.15.2)
  • Red Hat Cert-Manager Operator For Red Hat Openshift 1.16: before v1.16.5-1760515757 (fixed in v1.16.5-1760515757)
  • Red Hat Openshift Compliance Operator 1: before 1.8.0 (fixed in 1.8.0)
  • Red Hat Openshift File Integrity Operator - Fio 1: before v1.3 (fixed in v1.3)
  • Red Hat Red Hat Discovery 2: before 2.0.1-1754478727 (fixed in 2.0.1-1754478727)
  • Red Hat Red Hat Enterprise Linux 10: before 0:2.12.5-8.el10_0 (fixed in 0:2.12.5-8.el10_0); before 0:1.1.39-8.el10_0 (fixed in 0:1.1.39-8.el10_0)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:2.9.1-6.el7_9.12 (fixed in 0:2.9.1-6.el7_9.12)
  • Red Hat Red Hat Enterprise Linux 8: before 0:2.9.7-21.el8_10.2 (fixed in 0:2.9.7-21.el8_10.2)
  • Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support: before 0:2.9.7-9.el8_2.4 (fixed in 0:2.9.7-9.el8_2.4)
  • Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:2.9.7-9.el8_4.7 (fixed in 0:2.9.7-9.el8_4.7)
  • Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 0:2.9.7-9.el8_4.7 (fixed in 0:2.9.7-9.el8_4.7)
  • Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:2.9.7-13.el8_6.11 (fixed in 0:2.9.7-13.el8_6.11)
  • Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service: before 0:2.9.7-13.el8_6.11 (fixed in 0:2.9.7-13.el8_6.11)
  • Red Hat Red Hat Enterprise Linux 8.6 Update Services For SAP Solutions: before 0:2.9.7-13.el8_6.11 (fixed in 0:2.9.7-13.el8_6.11)
  • Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 0:2.9.7-16.el8_8.10 (fixed in 0:2.9.7-16.el8_8.10)
  • Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 0:2.9.7-16.el8_8.10 (fixed in 0:2.9.7-16.el8_8.10)
  • Red Hat Red Hat Enterprise Linux 9: before 0:2.9.13-11.el9_6 (fixed in 0:2.9.13-11.el9_6)
  • Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 0:2.9.13-1.el9_0.6 (fixed in 0:2.9.13-1.el9_0.6)
  • Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:2.9.13-3.el9_2.8 (fixed in 0:2.9.13-3.el9_2.8)
  • Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 0:2.9.13-11.el9_4 (fixed in 0:2.9.13-11.el9_4)
  • Red Hat Red Hat Hardened Images: before 2.15.3-0.1.hum1 (fixed in 2.15.3-0.1.hum1)
  • Red Hat Red Hat Insights Proxy 1.5: before 1.5.5-1754504343 (fixed in 1.5.5-1754504343)
  • Red Hat Red Hat Openshift Container Platform 4
  • Red Hat Red Hat Openshift Container Platform 4.12: before 412.86.202509030110-0 (fixed in 412.86.202509030110-0)
  • and 27 more

Published 2025-07-10. Last modified 2026-09-21.