CVE Vulnerabilities

CVE-2025-10911

Expired Pointer Dereference

Published: Sep 25, 2025 | Modified: Jun 26, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.

Weakness

The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatlibxslt-0:1.1.39-8.el10_2.1*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatlibxslt-0:1.1.39-8.el10_0.1*
Red Hat Enterprise Linux 8RedHatlibxslt-0:1.1.32-6.4.el8_10*
Red Hat Enterprise Linux 8RedHatlibxslt-0:1.1.32-6.4.el8_10*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatlibxslt-0:1.1.32-8.el8_4.1*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatlibxslt-0:1.1.32-8.el8_4.1*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatlibxslt-0:1.1.32-8.el8_8.1*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatlibxslt-0:1.1.32-8.el8_8.1*
Red Hat Enterprise Linux 9RedHatlibxslt-0:1.1.34-14.el9_8.1*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatlibxslt-0:1.1.34-12.el9_2*
Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsRedHatlibxslt-0:1.1.34-15.el9_4*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatlibxslt-0:1.1.34-13.el9_6.2*
Red Hat Hardened ImagesRedHatlibxslt-main-1.1.45-0.1.hum1*
LibxsltUbuntudevel*
LibxsltUbuntuesm-infra/xenial*
LibxsltUbuntuplucky*
LibxsltUbunturesolute*
LibxsltUbuntuupstream*

Potential Mitigations

References