Access of Resource Using Incompatible Type ('Type Confusion') The advisory has been revoked - it doesn't affect any version of package libxslt-devel  (opens in a new tab)


Threat Intelligence

EPSS
4.16% (90th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL10-LIBXSLTDEVEL-12229642
  • published29 Aug 2025
  • disclosed26 Aug 2015

Introduced: 26 Aug 2015

CVE-2015-7995  (opens in a new tab)
CWE-843  (opens in a new tab)

Amendment

The Red Hat security team deemed this advisory irrelevant for RHEL:10.

NVD Description

Note: Versions mentioned in the description apply only to the upstream libxslt-devel package and not the libxslt-devel package as distributed by RHEL.

The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.