CVE-2025-10911

Published: September 26, 2025Last modified: November 21, 2025

Description

A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.

Severity score breakdown

ParameterValue
Base score5.5
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibxsltUnknown (1.1.37-r0)
25 LTSlibxsltUnknown (1.1.43-r0)
StreamlibxsltUnknown (1.1.37-r0)
Liberica JDK8jdk-fullFixed (8u472+11)
jre-fullFixed (8u472+11)
11jdk-fullFixed (11.0.29+12)
jre-fullFixed (11.0.29+12)
17jdk-fullFixed (17.0.17+15)
jre-fullFixed (17.0.17+15)
21jdk-fullFixed (21.0.9+15)
jre-fullFixed (21.0.9+15)
25jdk-fullFixed (25.0.1+13)
jre-fullFixed (25.0.1+13)

References

Published BELL-SAs

ON THIS PAGE