Description
A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.
Problem types
Product status
Any version
Timeline
2025-09-24: | Reported to Red Hat. |
2025-08-04: | Made public. |
References
access.redhat.com/security/cve/CVE-2025-10911
bugzilla.redhat.com/show_bug.cgi?id=2397838 (RHBZ#2397838)
gitlab.gnome.org/GNOME/libxslt/-/issues/144
gitlab.gnome.org/GNOME/libxslt/-/merge_requests/77