VDB

RHSA-2025%3A14853

RHSA-2025%3A14853 PUBLISHED CVSS 7.800000190734863 HIGH

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H

Affected Products

VendorProductVersions
Red Hatrhcos-aarch64-414.92.202508270040-0 as a component of Red Hat OpenShift Container Platform 4.14rhcos-aarch64-414.92.202508270040-0
Red Hatrhcos-s390x-414.92.202508270040-0 as a component of Red Hat OpenShift Container Platform 4.14rhcos-s390x-414.92.202508270040-0
Red Hatrhcos-x86_64-414.92.202508270040-0 as a component of Red Hat OpenShift Container Platform 4.14rhcos-x86_64-414.92.202508270040-0
Red Hatrhcos-ppc64le-414.92.202508270040-0 as a component of Red Hat OpenShift Container Platform 4.14rhcos-ppc64le-414.92.202508270040-0

Timeline

  • Sep 4, 2025 CVE Published
  • Apr 30, 2026 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›