CVE-2025-7425

EUVD-2025-20998
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
siemens-SADPADP
7.8 HIGH
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
SiemensRUGGEDCOM ROX MX5000
𝑥
< V2.17.1
ADP
SiemensRUGGEDCOM ROX MX5000RE
𝑥
< V2.17.1
ADP
SiemensRUGGEDCOM ROX RX1400
𝑥
< V2.17.1
ADP
SiemensRUGGEDCOM ROX RX1500
𝑥
< V2.17.1
ADP
SiemensRUGGEDCOM ROX RX1501
𝑥
< V2.17.1
ADP
SiemensRUGGEDCOM ROX RX1510
𝑥
< V2.17.1
ADP
SiemensRUGGEDCOM ROX RX1511
𝑥
< V2.17.1
ADP
SiemensRUGGEDCOM ROX RX1512
𝑥
< V2.17.1
ADP
SiemensRUGGEDCOM ROX RX1524
𝑥
< V2.17.1
ADP
SiemensRUGGEDCOM ROX RX1536
𝑥
< V2.17.1
ADP
SiemensRUGGEDCOM ROX RX5000
𝑥
< V2.17.1
ADP
SiemensSIMATIC CN 4100
𝑥
< V5.0
ADP
SiemensSIMATIC S7-1500 CPU 1518-4 PN\/DP MFP
V3.1.5 ≤
𝑥
< *
ADP
SiemensSIMATIC S7-1500 CPU 1518-4 PN\/DP MFP
V3.1.5 ≤
𝑥
< *
ADP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN\/DP MFP
V3.1.5 ≤
𝑥
< *
ADP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN\/DP MFP
V3.1.5 ≤
𝑥
< *
ADP
SiemensSIMATIC S7-1500 TM MFP - GNU\/Linux subsystem
𝑥
< *
ADP
SiemensSIPLUS S7-1500 CPU 1518-4 PN\/DP MFP
V3.1.5 ≤
𝑥
< *
ADP
siemenssimatic_cn_4100
𝑥
< 5.0
ADP
Debian logo
Debian Releases
Debian Product
Codename
libxslt
bookworm
1.1.35-1+deb12u4
fixed
bookworm (security)
1.1.35-1+deb12u3
fixed
bullseye
1.1.34-4+deb11u1
fixed
bullseye (security)
1.1.34-4+deb11u3
fixed
forky
vulnerable
sid
vulnerable
trixie
1.1.35-1.2+deb13u3
fixed
trixie (security)
1.1.35-1.2+deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libxslt
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
deferred
oracular
ignored
plucky
ignored
questing
deferred
resolute
deferred
trusty
not-affected
xenial
not-affected
libxml2
bionic
Fixed 2.9.4+dfsg1-6.1ubuntu1.9+esm6
released
focal
Fixed 2.9.10+dfsg-5ubuntu0.20.04.10+esm3
released
jammy
Fixed 2.9.13+dfsg-1ubuntu0.10
released
noble
Fixed 2.9.14+dfsg-1.3ubuntu3.6
released
plucky
Fixed 2.12.7+dfsg+really2.9.14-0.4ubuntu0.4
released
questing
not-affected
resolute
not-affected
trusty
Fixed 2.9.1+dfsg1-3ubuntu4.13+esm10
released
xenial
Fixed 2.9.3+dfsg1-1ubuntu0.7+esm11
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libxml2-2
suse enterprise desktop 15 SP6
2.10.3-150500.5.32.1
fixed
suse enterprise desktop 15 SP7
2.12.10-150700.4.6.1
fixed
suse enterprise sap 15 SP6
2.10.3-150500.5.32.1
fixed
suse enterprise sap 15 SP7
2.12.10-150700.4.6.1
fixed
suse enterprise server 12 SP3
2.9.4-46.90.1
fixed
suse enterprise server 12 SP5
2.9.4-46.90.1
fixed
suse enterprise server 15 SP2
2.9.7-150000.3.85.1
fixed
suse enterprise server 15 SP3
2.9.7-150000.3.85.1
fixed
suse enterprise server 15 SP4
2.9.14-150400.5.47.1
fixed
suse enterprise server 15 SP5
2.10.3-150500.5.32.1
fixed
suse enterprise server 15 SP6
2.10.3-150500.5.32.1
fixed
suse enterprise server 15 SP7
2.12.10-150700.4.6.1
fixed
libxml2-2-32bit
suse enterprise desktop 15 SP6
2.10.3-150500.5.32.1
fixed
suse enterprise desktop 15 SP7
2.12.10-150700.4.6.1
fixed
suse enterprise sap 15 SP6
2.10.3-150500.5.32.1
fixed
suse enterprise sap 15 SP7
2.12.10-150700.4.6.1
fixed
suse enterprise server 12 SP3
2.9.4-46.90.1
fixed
suse enterprise server 12 SP5
2.9.4-46.90.1
fixed
suse enterprise server 15 SP2
2.9.7-150000.3.85.1
fixed
suse enterprise server 15 SP3
2.9.7-150000.3.85.1
fixed
suse enterprise server 15 SP4
2.9.14-150400.5.47.1
fixed
suse enterprise server 15 SP5
2.10.3-150500.5.32.1
fixed
suse enterprise server 15 SP6
2.10.3-150500.5.32.1
fixed
suse enterprise server 15 SP7
2.12.10-150700.4.6.1
fixed
libxml2-devel
suse enterprise desktop 15 SP6
2.10.3-150500.5.32.1
fixed
suse enterprise desktop 15 SP7
2.12.10-150700.4.6.1
fixed
suse enterprise sap 15 SP6
2.10.3-150500.5.32.1
fixed
suse enterprise sap 15 SP7
2.12.10-150700.4.6.1
fixed
suse enterprise server 12 SP5
2.9.4-46.90.1
fixed
suse enterprise server 15 SP2
2.9.7-150000.3.85.1
fixed
suse enterprise server 15 SP3
2.9.7-150000.3.85.1
fixed
suse enterprise server 15 SP4
2.9.14-150400.5.47.1
fixed
suse enterprise server 15 SP5
2.10.3-150500.5.32.1
fixed
suse enterprise server 15 SP6
2.10.3-150500.5.32.1
fixed
suse enterprise server 15 SP7
2.12.10-150700.4.6.1
fixed
libxml2-doc
suse enterprise server 12 SP3
2.9.4-46.90.1
fixed
suse enterprise server 12 SP5
2.9.4-46.90.1
fixed
libxml2-tools
suse enterprise desktop 15 SP6
2.10.3-150500.5.32.1
fixed
suse enterprise desktop 15 SP7
2.12.10-150700.4.6.1
fixed
suse enterprise sap 15 SP6
2.10.3-150500.5.32.1
fixed
suse enterprise sap 15 SP7
2.12.10-150700.4.6.1
fixed
suse enterprise server 12 SP3
2.9.4-46.90.1
fixed
suse enterprise server 12 SP5
2.9.4-46.90.1
fixed
suse enterprise server 15 SP2
2.9.7-150000.3.85.1
fixed
suse enterprise server 15 SP3
2.9.7-150000.3.85.1
fixed
suse enterprise server 15 SP4
2.9.14-150400.5.47.1
fixed
suse enterprise server 15 SP5
2.10.3-150500.5.32.1
fixed
suse enterprise server 15 SP6
2.10.3-150500.5.32.1
fixed
suse enterprise server 15 SP7
2.12.10-150700.4.6.1
fixed
python-libxml2
suse enterprise server 12 SP3
2.9.4-46.90.1
fixed
suse enterprise server 12 SP5
2.9.4-46.90.1
fixed
python2-libxml2-python
suse enterprise server 15 SP2
2.9.7-150000.3.85.1
fixed
python3-libxml2
suse enterprise desktop 15 SP6
2.10.3-150500.5.32.1
fixed
suse enterprise desktop 15 SP7
2.12.10-150700.4.6.1
fixed
suse enterprise sap 15 SP6
2.10.3-150500.5.32.1
fixed
suse enterprise sap 15 SP7
2.12.10-150700.4.6.1
fixed
suse enterprise server 15 SP4
2.9.14-150400.5.47.1
fixed
suse enterprise server 15 SP5
2.10.3-150500.5.32.1
fixed
suse enterprise server 15 SP6
2.10.3-150500.5.32.1
fixed
suse enterprise server 15 SP7
2.12.10-150700.4.6.1
fixed
python3-libxml2-python
suse enterprise server 15 SP2
2.9.7-150000.3.85.1
fixed
suse enterprise server 15 SP3
2.9.7-150000.3.85.1
fixed
python311-libxml2
suse enterprise server 15 SP4
2.9.14-150400.5.47.1
fixed
suse enterprise server 15 SP5
2.10.3-150500.5.32.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libxml2
RHEL 8
0:2.9.7-21.el8_10.2
fixed
RHEL 8.2 AUS
0:2.9.7-9.el8_2.4
fixed
RHEL 8.4 AUS
0:2.9.7-9.el8_4.7
fixed
RHEL 8.6 AUS
0:2.9.7-13.el8_6.11
fixed
RHEL 8.6 E4S
0:2.9.7-13.el8_6.11
fixed
RHEL 8.6 TUS
0:2.9.7-13.el8_6.11
fixed
RHEL 8.8 E4S
0:2.9.7-16.el8_8.10
fixed
RHEL 8.8 TUS
0:2.9.7-16.el8_8.10
fixed
RHEL 9
0:2.9.13-11.el9_6
fixed
libxml2-devel
RHEL 8
0:2.9.7-21.el8_10.2
fixed
RHEL 8.2 AUS
0:2.9.7-9.el8_2.4
fixed
RHEL 8.4 AUS
0:2.9.7-9.el8_4.7
fixed
RHEL 8.6 AUS
0:2.9.7-13.el8_6.11
fixed
RHEL 8.6 E4S
0:2.9.7-13.el8_6.11
fixed
RHEL 8.6 TUS
0:2.9.7-13.el8_6.11
fixed
RHEL 8.8 E4S
0:2.9.7-16.el8_8.10
fixed
RHEL 8.8 TUS
0:2.9.7-16.el8_8.10
fixed
RHEL 9
0:2.9.13-11.el9_6
fixed
python3-libxml2
RHEL 8
0:2.9.7-21.el8_10.2
fixed
RHEL 8.2 AUS
0:2.9.7-9.el8_2.4
fixed
RHEL 8.4 AUS
0:2.9.7-9.el8_4.7
fixed
RHEL 8.6 AUS
0:2.9.7-13.el8_6.11
fixed
RHEL 8.6 E4S
0:2.9.7-13.el8_6.11
fixed
RHEL 8.6 TUS
0:2.9.7-13.el8_6.11
fixed
RHEL 8.8 E4S
0:2.9.7-16.el8_8.10
fixed
RHEL 8.8 TUS
0:2.9.7-16.el8_8.10
fixed
RHEL 9
0:2.9.13-11.el9_6
fixed
References