Use-After-Free vulnerability in libxslt caused by unsafe manipulation of the atype field in attribute nodes. The flaw occurs when xsltSetSourceNodeFlags() sets extra flag bits on xmlAttrPtr->atype, a field later used by libxml2 to check whether an attribute is an XML ID. This corruption can cause libxml2 to skip cleanup steps like xmlRemoveID() during memory deallocation. As a result, ID table entries may point to freed memory, and later calls to xmlFreeID() will dereference these dangling pointers, triggering a use-after-free. This vulnerability is exploitable through crafted XSLT using the key() function and result tree fragments, and may result in denial-of-service or memory corruption.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:12447 https://access.redhat.com/errata/RHSA-2025:12447
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:12450 https://access.redhat.com/errata/RHSA-2025:12450
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:13309 https://access.redhat.com/errata/RHSA-2025:13309
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:13308 https://access.redhat.com/errata/RHSA-2025:13308
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2025:13310 https://access.redhat.com/errata/RHSA-2025:13310
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:13311 https://access.redhat.com/errata/RHSA-2025:13311
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2025:13313 https://access.redhat.com/errata/RHSA-2025:13313
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:13312 https://access.redhat.com/errata/RHSA-2025:13312
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:13314 https://access.redhat.com/errata/RHSA-2025:13314
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:13464 https://access.redhat.com/errata/RHSA-2025:13464
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:14059 https://access.redhat.com/errata/RHSA-2025:14059
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2025:14396 https://access.redhat.com/errata/RHSA-2025:14396
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2025:14819 https://access.redhat.com/errata/RHSA-2025:14819
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2025:14818 https://access.redhat.com/errata/RHSA-2025:14818
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2025:14853 https://access.redhat.com/errata/RHSA-2025:14853
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2025:14858 https://access.redhat.com/errata/RHSA-2025:14858
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2025:15308 https://access.redhat.com/errata/RHSA-2025:15308
This issue has been addressed in the following products: Red Hat Web Terminal 1.12 on RHEL 9 Via RHSA-2025:15827 https://access.redhat.com/errata/RHSA-2025:15827
This issue has been addressed in the following products: Red Hat Web Terminal 1.11 on RHEL 9 Via RHSA-2025:15828 https://access.redhat.com/errata/RHSA-2025:15828
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2025:15672 https://access.redhat.com/errata/RHSA-2025:15672