Use-after-free in libxslt - CVE-2024-55549
Published: March 19, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in xsltGetInheritedNsList. A remote attacker can pass specially crafted input to the application, trigger a use-after-free error and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Oracle Linux
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Debian Linux
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
visionOS
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Anolis OS
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
watchOS
macOS
Ubuntu
Slackware Linux
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
iPadOS
tvOS
Apple iOS
openEuler
Fedora
Rapid Infrastructure Automation
IBM Cloud Pak for Watson AIOps
SmartFabric OS10
Netcool Operations Insight
Tenable Nessus
IBM Observability with Instana
APEX Cloud Platform for Red Hat OpenShift
OpenShift Logging
Session Smart Router
Financial Transaction Manager
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libxslt (Ubuntu package)
libxslt (Red Hat package)
libxslt-python
libxslt-devel
libxslt
libxslt-tools-debuginfo
libxslt-tools
libxslt1
libxslt1-debuginfo-32bit
libxslt1-32bit
libxslt-debugsource
libxslt1-debuginfo
libxslt-python-debugsource
libxslt-python-debuginfo
libxslt1.1 (Ubuntu package)
libxslt1-64bit
libxslt1-32bit-debuginfo
libxslt-devel-32bit
libxslt1-64bit-debuginfo
libxslt-devel-64bit
libxslt (Debian package)
libxslt-debuginfo
python3-libxslt
libxslt-help
libxslt-doc
mingw-libxslt
IBM API Connect
SmartFabric Manager
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
Traffix SDC
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Ceph Storage
PowerScale OneFS
IBM App Connect Enterprise
How to mitigate CVE-2024-55549
visionOS - update to 2.3
Rapid Infrastructure Automation - update to 1.1.5.3
Netcool Operations Insight - update to 1.6.15
Financial Transaction Manager - addressed in versions 3.2.13 iFix4, 4.0.6.0 iFix5, 4.0.7.0
IBM Cloud Pak for Watson AIOps - update to 4.10.0
Tenable Nessus - addressed in versions 10.8.0, 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5, 10.8.6, 10.9.6, 10.11.1
IBM API Connect - update to 10.0.8.5
watchOS - update to 11.3
macOS - addressed in versions 13.7.3 22H417, 14.7.3 23H417, 15.3 24D60
iPadOS - addressed in versions 17.7.4, 18.3 22D60
tvOS - update to 18.3
Apple iOS - update to 18.3 22D60
IBM Observability with Instana - update to 1.0.295
libxslt (Ubuntu package) - addressed in versions 1.1.28-2ubuntu0.2+esm4, 1.1.28-2.1ubuntu0.3+esm3, 1.1.29-5ubuntu0.3+esm2
libxslt (Red Hat package) - addressed in versions 1.1.28-8.el7_9, 1.1.28-9.el7_9, 1.1.32-6.el8_2, 1.1.32-6.1.el8_10, 1.1.32-8.el8_4, 1.1.34-9.el9_5.2, 1.1.34-11.el9_0, 1.1.34-11.el9_2, 1.1.34-13.el9_4, 1.1.34-13.el9_6
libxslt-python - addressed in versions 1.1.28-8.0.1, 1.1.28-9.0.1
libxslt-devel - addressed in versions 1.1.28-8.0.1, 1.1.28-9.0.1, 1.1.32-6.1.0.1, 1.1.43-1
libxslt - addressed in versions 1.1.28-8.0.1, 1.1.28-9.0.1, 1.1.32-6.1.0.1, 1.1.43-1
libxslt-tools-debuginfo - addressed in versions 1.1.28-17.18.1, 1.1.32-150000.3.17.1, 1.1.34-150400.3.6.1
libxslt-tools - addressed in versions 1.1.28-17.18.1, 1.1.32-150000.3.17.1, 1.1.34-150400.3.6.1
libxslt1 - addressed in versions 1.1.28-17.18.1, 1.1.32-150000.3.17.1, 1.1.34-150400.3.6.1
libxslt1-debuginfo-32bit - update to 1.1.28-17.18.1
libxslt1-32bit - addressed in versions 1.1.28-17.18.1, 1.1.34-150400.3.6.1
libxslt-debugsource - addressed in versions 1.1.28-17.18.1, 1.1.32-150000.3.17.1, 1.1.34-150400.3.6.1
libxslt-devel - addressed in versions 1.1.28-17.18.1, 1.1.32-150000.3.17.1, 1.1.34-150400.3.6.1
libxslt1-debuginfo - addressed in versions 1.1.28-17.18.1, 1.1.32-150000.3.17.1, 1.1.34-150400.3.6.1
libxslt-python - update to 1.1.32-150000.3.17.1
libxslt-python-debugsource - update to 1.1.32-150000.3.17.1
libxslt-python-debuginfo - update to 1.1.32-150000.3.17.1
libxslt1.1 (Ubuntu package) - addressed in versions 1.1.34-4ubuntu0.20.04.2, 1.1.34-4ubuntu0.22.04.2, 1.1.39-0exp1ubuntu0.24.04.1, 1.1.39-0exp1ubuntu1.1
libxslt1-64bit - update to 1.1.34-150400.3.6.1
libxslt1-32bit-debuginfo - update to 1.1.34-150400.3.6.1
libxslt-devel-32bit - update to 1.1.34-150400.3.6.1
libxslt1-64bit-debuginfo - update to 1.1.34-150400.3.6.1
libxslt-devel-64bit - update to 1.1.34-150400.3.6.1
libxslt (Debian package) - update to 1.1.35-1+deb12u1
libxslt-devel - update to 1.1.37-2
libxslt - update to 1.1.37-2
libxslt-debuginfo - update to 1.1.37-2
libxslt-debugsource - update to 1.1.37-2
python3-libxslt - update to 1.1.37-2
libxslt-help - update to 1.1.37-2
libxslt - update to 1.1.43
libxslt-doc - update to 1.1.43-1
python3-libxslt - update to 1.1.43-1
mingw-libxslt - addressed in versions 1.1.43-1.fc40, 1.1.43-1.fc41, 1.1.43-1.fc42
SmartFabric Manager - update to 1.3.0
Migration Toolkit for Containers - update to 1.8.7
IBM Cloud Pak for Multicloud Management - update to 2.3 FP11
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
Red Hat OpenShift Container Platform - addressed in versions 4.12.76, 4.12.77, 4.13.57, 4.13.58, 4.14.51, 4.14.52, 4.15.49, 4.15.50, 4.16.39, 4.16.40, 4.17.25, 4.17.28, 4.18.9, 4.18.12
OpenShift Virtualization - update to 4.16.7
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.17.7
Traffix SDC - update to 5.2.0 CF8
OpenShift Logging - update to 5.8.20
Session Smart Router - addressed in versions 6.2.10, 6.3.7
Red Hat Ceph Storage - update to 8.1
PowerScale OneFS - addressed in versions 9.10.1.3, 9.11.0.1
SmartFabric OS10 - addressed in versions 10.5.4.15, 10.5.5.14, 10.5.6.9, 10.6.0.3
IBM App Connect Enterprise - addressed in versions 12.0.12, 12.12.0
External References
Related Security Bulletins
- Remote code execution in libxslt
- Ubuntu update for libxslt
- Slackware Linux update for libxslt
- openEuler update for libxslt
- Fedora 41 update for mingw-libxslt
- Fedora 40 update for mingw-libxslt
- Fedora 42 update for mingw-libxslt
- Debian update for libxslt
- SUSE update for libxslt
- SUSE update for libxslt
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for libxslt
- Red Hat Enterprise Linux 9 update for libxslt
- Red Hat Enterprise Linux 9 update for libxslt
- Red Hat Enterprise Linux 8 update for libxslt
- Red Hat Enterprise Linux 8 update for libxslt
- Red Hat Enterprise Linux 8 update for libxslt
- Red Hat Enterprise Linux 9 update for libxslt
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Anolis OS update for libxslt
- Red Hat Enterprise Linux 9 update for libxslt
- Multiple vulnerabilities in OpenShift Virtualization 4.16
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for libxslt
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Anolis OS update for libxslt
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- SUSE update for libxslt
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Red Hat Enterprise Linux 9 update for libxslt
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Dell SmartFabric OS10
- Multiple vulnerabilities in macOS Sequoia
- Multiple vulnerabilities in Apple iOS 18 and iPadOS 18
- Multiple vulnerabilities in Apple visionOS
- Multiple vulnerabilities in Apple iPadOS 17
- Multiple vulnerabilities in Apple macOS Sonoma
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple tvOS
- Dell SmartFabric OS10 update for third-party components
- Multiple vulnerabilities in Dell Networking OS10
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Dell Networking OS10 update for third-party components
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in IBM Rapid Infrastructure Automation
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Anolis OS update for libxslt
- Multiple vulnerabilities in IBM Financial Transaction Manager (FTM) for RedHat OpenShift
- Dell SmartFabric Manager update for third-party components
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Anolis OS update for libxslt
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- Multiple vulnerabilities in Red Hat Ceph Storage 8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Dell PowerScale OneFS update for third-party components
- Traffix SDC update for libxslt
- Ubuntu update for libxslt
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in Tenable Nessus
- Juniper Session Smart Router update for third-party components