REDHAT-BUG-2379274: Use After Free

Published Jul 10, 2025
·
Updated

Use-After-Free vulnerability in libxslt caused by unsafe manipulation of the atype field in attribute nodes. The flaw occurs when xsltSetSourceNodeFlags() sets extra flag bits on xmlAttrPtr->atype, a field later used by libxml2 to check whether an attribute is an XML ID. This corruption can cause libxml2 to skip cleanup steps like xmlRemoveID() during memory deallocation. As a result, ID table entries may point to freed memory, and later calls to xmlFreeID() will dereference these dangling pointers, triggering a use-after-free. This vulnerability is exploitable through crafted XSLT using the key() function and result tree fragments, and may result in denial-of-service or memory corruption.

Affected Software

1 affected component
Libxml2 libxslt

Event History

Jul 10, 2025
Data Sourced
via Red Hat·09:47 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2379274?

The severity of REDHAT-BUG-2379274 is classified as a critical vulnerability.

2

How do I fix REDHAT-BUG-2379274?

To fix REDHAT-BUG-2379274, update to the latest version of libxslt where the vulnerability is addressed.

3

What causes the vulnerability identified by REDHAT-BUG-2379274?

The vulnerability identified by REDHAT-BUG-2379274 is caused by unsafe manipulation of the atype field in attribute nodes in libxslt.

4

Which software is affected by REDHAT-BUG-2379274?

The affected software for REDHAT-BUG-2379274 is Libxml2 libxslt.

5

What are the potential impacts of REDHAT-BUG-2379274?

The potential impacts of REDHAT-BUG-2379274 include corruption of XML attribute information leading to security issues.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203