Home

Description

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.

PUBLISHED Reserved 2025-01-26 | Published 2025-03-14 | Updated 2025-11-03 | Assigner mitre




HIGH: 7.8CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H

Problem types

CWE-416 Use After Free

Product status

Default status
unaffected

Any version before 1.1.43
affected

References

lists.debian.org/debian-lts-announce/2025/03/msg00015.html

gitlab.gnome.org/GNOME/libxslt/-/issues/128

cve.org (CVE-2025-24855)

nvd.nist.gov (CVE-2025-24855)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.