A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected memory reads and potential crashes. While difficult to exploit, the flaw could lead to application instability or denial of service.
CVSS Details
- CVSS 3.1 Base Score: 3.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Dell Powerstore Dsa2026115 | — | Upgrade Dell PowerStoreOS to the latest version | Feb 25, 2026 | Feb 24, 2026 |
| Freebsd | — | Upgrade linux-rl9-libxsltUpgrade linux-c7-libxsltUpgrade libxslt | Jan 27, 2026 | Jul 12, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Oct 14, 2025 |
| Suse | — | Upgrade libxslt1-32bitUpgrade libxslt-pythonUpgrade libxslt1Upgrade libxslt-toolsUpgrade libxslt-devel-32bitUpgrade libxslt-devel | Dec 5, 2025 | Oct 24, 2025 |
| Ubuntu | — | Upgrade libxslt | May 25, 2026 | Oct 14, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 29, 2026 | Oct 14, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub