CVE-2025-7424 @ mufasa
Status
new
Priority
6.06
Match score
3.0
Risk
DoS
Remote
CVSS
7.5 HIGH
Reason
cpe: libxslt; pkgs: libxslt, libxslt-devel; version: unknown (libxslt-1.1.28-6.el7; libxslt-devel-1.1.28-6.el7); risk:dos
Created
2026-08-22T10:15:32Z
Updated
2026-08-22T10:15:32Z
Package interrogation (copy)
Run on the host — click to copy a command. RPM
| Package | Commands |
|---|---|
| libxslt-1.1.28-6.el7 | |
| libxslt-devel-1.1.28-6.el7) |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: libxslt · libxslt-devel
| System | Matches | Ticket for CVE-2025-7424 | |
|---|---|---|---|
| morris | libxslt 1.1.28; libxslt-devel 1.1.28 | new open | |
| mufasa | libxslt 1.1.28; libxslt-devel 1.1.28 | new open | |
| Archive | libxslt1.1 1.1.32-2.2~deb10u2 | none | |
| Bullseye | libxslt1.1 1.1.34-4+deb11u3 | none | |
| Library | libxslt1.1 1.1.29-2.1+deb9u2 | none | |
| Matrix | libxslt1.1 1.1.35-1+deb12u4 | none | |
| Saiph | libxslt1.1 1.1.32-2.2~deb10u2 | none | |
| Silk | libxslt1.1 1.1.35-1+deb12u4 | none |
Related CVE (same fix)
Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.
Host OS / kernel
OS
CloudLinux release 7.9 (Boris Yegorov)
(7.9)
· cloudlinux
Arch
x86_64
kernel_release
uname -r → 3.10.0-962.3.2.lve1.5.89.el7.x86_64kernel_version
uname -v → #1 SMP Thu Jul 9 15:55:31 UTC 2026For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Same CVE on other hosts
Open the ticket for this CVE on another system.
| System | Status | Priority | Updated | |
|---|---|---|---|---|
| morris | new | 6.06 | 2026-08-22T10:15:32Z | Open |
Description
A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt memory. In some cases, it may lead to denial of service or unexpected behavior.
Update status
Add note only
References
- https://access.redhat.com/errata/RHBA-2025:12345
- https://access.redhat.com/errata/RHSA-2026:11015
- https://access.redhat.com/security/cve/CVE-2025-7424
- https://bugzilla.redhat.com/show_bug.cgi?id=2379228
- https://gitlab.gnome.org/GNOME/libxslt/-/issues/139
- http://seclists.org/fulldisclosure/2025/Aug/0
- http://seclists.org/fulldisclosure/2025/Jul/30
- http://seclists.org/fulldisclosure/2025/Jul/32
- http://seclists.org/fulldisclosure/2025/Jul/33
- http://seclists.org/fulldisclosure/2025/Jul/35
- http://seclists.org/fulldisclosure/2025/Jul/37
- http://www.openwall.com/lists/oss-security/2025/07/11/2
- https://lists.debian.org/debian-lts-announce/2025/09/msg00024.html
NVD: CVE-2025-7424