PT-2025-11227 · Libxslt+13 · Libxslt+13

CVE-2025-24855

·

Publicado

2024-12-17

·

Atualizado

2026-06-08

CVSS v3.1

7.8

Alta

VetorAV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
Nome do Software Vulnerável e Versões Afetadas: Versões do libxslt anteriores à 1.1.43
Descrição: O problema está relacionado a um erro de use-after-free no arquivo numbers.c do libxslt. Isso ocorre durante avaliações XPath aninhadas, nas quais um nó de contexto XPath pode ser modificado, mas nunca restaurado. As funções xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs e xsltComputeSortResultInternal estão envolvidas neste problema.
Recomendações: Para versões anteriores à 1.1.43, atualize para a versão 1.1.43 ou posterior para resolver o problema. Como solução temporária, considere restringir o uso de avaliações XPath aninhadas até que um patch esteja disponível.

Exploit

Correção

DoS

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025:3107
ALSA-2025:3615
ALSA-2025:7496
ALT-PU-2025-13573
AZL-58644
AZL-58665
BDU:2025-03640
BIT-JAVA-2025-24855
BIT-JAVA-MIN-2025-24855
BIT-JRE-2025-24855
CESA-2025_3615
CVE-2025-24855
DLA-4089-1
DSA-5884-1
GHSA-MRXW-MXHJ-P664
INFSA-2025_3107
INFSA-2025_3615
JLSEC-2026-583
MGASA-2025-0110
OESA-2025-1296
OPENSUSE-SU-2025:14894-1
OPENSUSE-SU-2025:15531-1
OPENSUSE-SU-2025_1003-1
OPENSUSE-SU-2025_1125-1
RHSA-2025:3107
RHSA-2025:3389
RHSA-2025:3528
RHSA-2025:3612
RHSA-2025:3615
RHSA-2025:3619
RHSA-2025:3624
RHSA-2025:3625
RHSA-2025:3626
RHSA-2025:3627
RHSA-2025:4098
RHSA-2025:7496
RHSA-2025_3107
RHSA-2025_3615
ROSA-SA-2025-2869
SUSE-SU-2025:1003-1
SUSE-SU-2025:1125-1
SUSE-SU-2025:1494-1
SUSE-SU-2025:20201-1
SUSE-SU-2025:20277-1
USN-7361-1
USN-7787-1

Produtos afetados

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Java Platform
Linuxmint
Apple Macos
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Libxslt