CVE-2025-7424: Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes
A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt memory. In some cases, it may lead to denial of service or unexpected behavior.
Other sources
Accessibility. A logic issue was addressed with improved checks.
— Apple
Accessibility. The issue was addressed by adding additional logic.
— Apple
Admin Framework. A path handling issue was addressed with improved validation.
— Apple
afclip. The issue was addressed with improved memory handling.
— Apple
AMD. A race condition was addressed with improved state handling.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.7.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.7.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.6
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43186
- CVE-2025-43223
- CVE-2025-43277
- CVE-2025-43210
- CVE-2025-43230
- CVE-2025-43209
- CVE-2025-43226
- CVE-2025-43282
- CVE-2025-7425
- CVE-2025-7424
- CVE-2025-43234
- CVE-2025-43224
- CVE-2025-43221
- CVE-2025-31281
- CVE-2025-6965
- CVE-2025-43227
- CVE-2025-31278
- CVE-2025-31277
- CVE-2025-31273
- CVE-2025-43214
- CVE-2025-43213
- CVE-2025-43212
- CVE-2025-43211
- CVE-2025-43265
- CVE-2025-43216
- CVE-2025-6558
- CVE-2025-31229
- CVE-2025-43217
- CVE-2025-43202
- CVE-2025-31276
- CVE-2025-43280
- CVE-2025-43228
- CVE-2025-43191
- CVE-2025-43244
- CVE-2025-31243
- CVE-2025-43253
- CVE-2025-43249
- CVE-2025-43248
- CVE-2025-43245
- CVE-2025-43222
- CVE-2025-43220
- CVE-2025-43199
- CVE-2025-43195
- CVE-2025-43313
- CVE-2025-43187
- CVE-2025-43198
- CVE-2025-43254
- CVE-2025-43261
- CVE-2025-31279
- CVE-2025-24119
- CVE-2025-43255
- CVE-2025-43284
- CVE-2025-43196
- CVE-2025-43192
- CVE-2025-43275
- CVE-2025-43270
- CVE-2025-43225
- CVE-2025-43266
- CVE-2025-43260
- CVE-2025-43247
- CVE-2025-43194
- CVE-2025-43232
- CVE-2025-43236
- CVE-2025-43241
- CVE-2025-43233
- CVE-2025-43193
- CVE-2025-43250
- CVE-2025-43184
- CVE-2025-43197
- CVE-2025-43239
- CVE-2025-43243
- CVE-2025-43246
- CVE-2025-43256
- CVE-2025-43206
- CVE-2025-43189
- CVE-2025-43259
- CVE-2025-43238
- CVE-2025-24224
- CVE-2025-24220
- CVE-2025-43281
- CVE-2025-43257
- CVE-2025-43273
- CVE-2025-43267
- CVE-2025-43188
- CVE-2025-43276
- CVE-2025-43268
- CVE-2025-31275
- CVE-2025-43264
- CVE-2025-43219
- CVE-2025-31280
- CVE-2025-43218
- CVE-2025-43215
- CVE-2025-43235
- CVE-2025-43274
- CVE-2025-24188
- CVE-2025-43251
- CVE-2025-43185
- CVE-2025-43237
- CVE-2025-43229
- CVE-2025-43240
- CVE-2025-43252
Frequently Asked Questions
What is the severity of CVE-2025-7424?
CVE-2025-7424 has been classified as a critical vulnerability due to the potential for application crashes and memory corruption.
How do I fix CVE-2025-7424?
To mitigate CVE-2025-7424, update the libxslt library to the latest version provided by the vendor.
What are the potential impacts of CVE-2025-7424?
CVE-2025-7424 can lead to application crashes, memory corruption, and potentially expose the system to further attacks.
Which software is affected by CVE-2025-7424?
CVE-2025-7424 specifically affects the GNOME libxslt library.
What type of attack can exploit CVE-2025-7424?
CVE-2025-7424 can be exploited through crafted XML transformations, potentially leading to arbitrary code execution.