Use-after-free in libxslt - CVE-2025-24855

 

Use-after-free in libxslt - CVE-2025-24855

Published: March 21, 2025


Vulnerability identifier: #VU105946
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-24855
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in numbers.c when handling nested XPath evaluations. A remote attacker can pass specially crafted XML input to the application, trigger a use-after-free error and execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

libxslt
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Oracle Linux
SUSE Linux Enterprise Server 15 SP3
Debian Linux
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
visionOS
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Anolis OS
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
watchOS
macOS
Ubuntu
Slackware Linux
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
iPadOS
tvOS
Apple iOS
openEuler
Fedora
Rapid Infrastructure Automation
SmartFabric OS10
Netcool Operations Insight
Tenable Nessus
IBM Observability with Instana
APEX Cloud Platform for Red Hat OpenShift
Cryostat
Session Smart Router
App Connect Enterprise Certified Container
Financial Transaction Manager
Oracle Java SE
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libxslt (Ubuntu package)
libxslt (Red Hat package)
libxslt
libxslt-devel
libxslt-python
libxslt-tools
libxslt1
libxslt1-debuginfo
libxslt1-debuginfo-32bit
libxslt-tools-debuginfo
libxslt1-32bit
libxslt-debugsource
libxslt-python-debugsource
libxslt-python-debuginfo
libxslt1.1 (Ubuntu package)
libxslt1-64bit-debuginfo
libxslt1-64bit
libxslt-devel-32bit
libxslt1-32bit-debuginfo
libxslt-devel-64bit
libxslt (Debian package)
libxslt-debuginfo
libxslt-doc
python3-libxslt
libxslt-help
mingw-libxslt
SmartFabric Manager
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
Traffix SDC
OpenShift Data Foundation (formerly OpenShift Container Storage)
PowerScale OneFS

How to mitigate CVE-2025-24855

Install updates from vendor's website.

libxslt - update to 1.1.43
visionOS - update to 2.3
Rapid Infrastructure Automation - update to 1.1.5.3
Netcool Operations Insight - update to 1.6.15
Financial Transaction Manager - addressed in versions 3.2.13 iFix4, 4.0.6.0 iFix5, 4.0.7.0
Tenable Nessus - update to 10.8.5
watchOS - update to 11.3
macOS - addressed in versions 13.7.3 22H417, 14.7.3 23H417, 15.3 24D60
iPadOS - addressed in versions 17.7.4, 18.3 22D60
tvOS - update to 18.3
Apple iOS - update to 18.3 22D60
IBM Observability with Instana - update to 1.0.295
libxslt (Ubuntu package) - addressed in versions 1.1.28-2ubuntu0.2+esm4, 1.1.28-2.1ubuntu0.3+esm3, 1.1.29-5ubuntu0.3+esm2
libxslt (Red Hat package) - addressed in versions 1.1.28-8.el7_9, 1.1.28-9.el7_9, 1.1.32-6.el8_2, 1.1.32-6.1.el8_10, 1.1.32-8.el8_4, 1.1.34-9.el9_5.1, 1.1.34-10.el9_4, 1.1.34-11.el9_0
libxslt - addressed in versions 1.1.28-8.0.1, 1.1.28-9.0.1, 1.1.32-6.1.0.1, 1.1.37-2
libxslt-devel - addressed in versions 1.1.28-8.0.1, 1.1.28-9.0.1, 1.1.32-6.1.0.1, 1.1.37-2
libxslt-python - addressed in versions 1.1.28-8.0.1, 1.1.28-9.0.1
libxslt-tools - addressed in versions 1.1.28-17.18.1, 1.1.32-150000.3.17.1, 1.1.34-150400.3.6.1
libxslt-devel - addressed in versions 1.1.28-17.18.1, 1.1.32-150000.3.17.1, 1.1.34-150400.3.6.1
libxslt1 - addressed in versions 1.1.28-17.18.1, 1.1.32-150000.3.17.1, 1.1.34-150400.3.6.1
libxslt1-debuginfo - addressed in versions 1.1.28-17.18.1, 1.1.32-150000.3.17.1, 1.1.34-150400.3.6.1
libxslt1-debuginfo-32bit - update to 1.1.28-17.18.1
libxslt-tools-debuginfo - addressed in versions 1.1.28-17.18.1, 1.1.32-150000.3.17.1, 1.1.34-150400.3.6.1
libxslt1-32bit - addressed in versions 1.1.28-17.18.1, 1.1.34-150400.3.6.1
libxslt-debugsource - addressed in versions 1.1.28-17.18.1, 1.1.32-150000.3.17.1, 1.1.34-150400.3.6.1
libxslt-python - update to 1.1.32-150000.3.17.1
libxslt-python-debugsource - update to 1.1.32-150000.3.17.1
libxslt-python-debuginfo - update to 1.1.32-150000.3.17.1
libxslt1.1 (Ubuntu package) - addressed in versions 1.1.34-4ubuntu0.20.04.3, 1.1.34-4ubuntu0.22.04.3, 1.1.39-0exp1ubuntu0.24.04.2, 1.1.39-0exp1ubuntu1.2
libxslt1-64bit-debuginfo - update to 1.1.34-150400.3.6.1
libxslt1-64bit - update to 1.1.34-150400.3.6.1
libxslt-devel-32bit - update to 1.1.34-150400.3.6.1
libxslt1-32bit-debuginfo - update to 1.1.34-150400.3.6.1
libxslt-devel-64bit - update to 1.1.34-150400.3.6.1
libxslt (Debian package) - update to 1.1.35-1+deb12u1
libxslt - update to 1.1.37-2
libxslt-debuginfo - update to 1.1.37-2
libxslt-debugsource - update to 1.1.37-2
libxslt-doc - update to 1.1.37-2
python3-libxslt - update to 1.1.37-2
libxslt-devel - update to 1.1.37-2
python3-libxslt - update to 1.1.37-2
libxslt-help - update to 1.1.37-2
libxslt - update to 1.1.43
mingw-libxslt - addressed in versions 1.1.43-1.fc40, 1.1.43-1.fc41, 1.1.43-1.fc42
SmartFabric Manager - update to 1.3.0
Migration Toolkit for Containers - update to 1.8.7
IBM Cloud Pak for Multicloud Management - update to 2.3 Fix Pack 12
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
Cryostat - update to 4.0.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.17.7
Red Hat OpenShift Container Platform - addressed in versions 4.12.77, 4.13.58, 4.14.50, 4.14.52, 4.15.49, 4.15.50, 4.16.40, 4.17.24, 4.17.28, 4.18.8, 4.18.12
Traffix SDC - update to 5.2.0 CF8
Session Smart Router - addressed in versions 6.2.10, 6.3.7
PowerScale OneFS - addressed in versions 9.10.1.3, 9.11.0.1
SmartFabric OS10 - addressed in versions 10.5.4.15, 10.5.5.14, 10.5.6.9, 10.6.0.3
App Connect Enterprise Certified Container - addressed in versions 12.0.11, 12.11.0

External References

Related Security Bulletins