vulnerability
Red Hat OpenShift: CVE-2025-24855: libxslt: Use-After-Free in libxslt numbers.c
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
6 | (AV:L/AC:H/Au:N/C:N/I:C/A:C) | Mar 14, 2025 | May 12, 2025 | May 22, 2025 |
Severity
6
CVSS
(AV:L/AC:H/Au:N/C:N/I:C/A:C)
Published
Mar 14, 2025
Added
May 12, 2025
Modified
May 22, 2025
Description
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.
Solution
linuxrpm-upgrade-rhcos
References
- CVE-2025-24855
- https://attackerkb.com/topics/CVE-2025-24855
- REDHAT-RHSA-2025:3107
- REDHAT-RHSA-2025:3389
- REDHAT-RHSA-2025:3528
- REDHAT-RHSA-2025:3612
- REDHAT-RHSA-2025:3615
- REDHAT-RHSA-2025:3619
- REDHAT-RHSA-2025:3624
- REDHAT-RHSA-2025:3625
- REDHAT-RHSA-2025:3626
- REDHAT-RHSA-2025:3627
- REDHAT-RHSA-2025:4098
- REDHAT-RHSA-2025:4422
- REDHAT-RHSA-2025:4427
- REDHAT-RHSA-2025:4431
- REDHAT-RHSA-2025:4677
- REDHAT-RHSA-2025:4731
- REDHAT-RHSA-2025:7496
- REDHAT-RHSA-2025:7702

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.