Intel

AIKIDO-2025-10406

GNOME.libxslt is vulnerable to Use-After-Free

Use-After-FreeCVE-2025-24855

78

High Risk

This Affects:

c++GNOME.libxslt
0.0.1 - 1.1.42
Fixed in 1.1.43

TL;DR

In libxslt versions before 1.1.43, a use-after-free vulnerability exists due to improper handling of the XPath context node during nested XPath evaluations. When the context node is modified but not restored, it leads to a use-after-free issue. This affects functions like xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

GNOME.libxslt is vulnerable to Use-After-Free in versions 0.0.1 - 1.1.42.

How to fix this

Upgrade the GNOME.libxslt library to the patch version.