Bug 2392605 (CVE-2025-9714) - CVE-2025-9714 libxslt: libxml2: Inifinite recursion at exsltDynMapFunction function in libexslt/dynamic.c
Summary: CVE-2025-9714 libxslt: libxml2: Inifinite recursion at exsltDynMapFunction fu...
Keywords:
Status: NEW
Alias: CVE-2025-9714
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2392608 2392609 2417576 2417577 2417578 2417579
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-09-02 13:26 UTC by OSIDB Bzimport
Modified: 2025-12-03 20:24 UTC (History)
16 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2025:22390 0 None None None 2025-12-01 06:25:15 UTC
Red Hat Product Errata RHBA-2025:22431 0 None None None 2025-12-01 15:58:11 UTC
Red Hat Product Errata RHBA-2025:22586 0 None None None 2025-12-02 13:29:05 UTC
Red Hat Product Errata RHBA-2025:22587 0 None None None 2025-12-02 12:14:16 UTC
Red Hat Product Errata RHBA-2025:22588 0 None None None 2025-12-02 12:14:45 UTC
Red Hat Product Errata RHBA-2025:22653 0 None None None 2025-12-03 01:12:04 UTC
Red Hat Product Errata RHBA-2025:22674 0 None None None 2025-12-03 20:24:46 UTC
Red Hat Product Errata RHSA-2025:22162 0 None None None 2025-11-26 05:23:21 UTC
Red Hat Product Errata RHSA-2025:22163 0 None None None 2025-11-26 05:33:24 UTC
Red Hat Product Errata RHSA-2025:22177 0 None None None 2025-11-26 13:13:27 UTC
Red Hat Product Errata RHSA-2025:22376 0 None None None 2025-12-01 03:11:17 UTC
Red Hat Product Errata RHSA-2025:22377 0 None None None 2025-12-01 03:15:58 UTC

Description OSIDB Bzimport 2025-09-02 13:26:06 UTC
A critical stack overflow vulnerability was discovered in the libxslt library when handling the dyn:map() function from the EXSLT extension. The vulnerability allows an attacker to cause a denial of service (DoS) via a specially crafted XSLT document containing the recursive dyn:map(., .) call.

The main reason of the vulnerability is that the exsltDynMapFunction function in libexslt/dynamic.c doesn’t contain a recursion depth check. When handling dyn:map(., .) where the second parameter contains a recursive call to the same function, infinite recursion occurs until the program stack is exhausted.

Comment 2 errata-xmlrpc 2025-11-26 05:23:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:22162 https://access.redhat.com/errata/RHSA-2025:22162

Comment 3 errata-xmlrpc 2025-11-26 05:33:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:22163 https://access.redhat.com/errata/RHSA-2025:22163

Comment 4 errata-xmlrpc 2025-11-26 13:13:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:22177 https://access.redhat.com/errata/RHSA-2025:22177

Comment 6 errata-xmlrpc 2025-12-01 03:11:15 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:22376 https://access.redhat.com/errata/RHSA-2025:22376

Comment 7 errata-xmlrpc 2025-12-01 03:15:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2025:22377 https://access.redhat.com/errata/RHSA-2025:22377


Note You need to log in before you can comment on or make changes to this bug.