Executive brief
A vulnerability was found in libxslt, a widely used library for processing XML documents. An attacker could provide a specially crafted stylesheet that causes applications using this library to crash or become unstable. While the risk of data theft is low, this flaw can lead to a denial of service, impacting the availability of systems that process untrusted XML content.
Technical details
A type confusion vulnerability exists in the exsltFuncResultComp() function within libxslt's EXSLT extension. When the function handles a <func:result> element, it traverses the node hierarchy to find a parent <func:function> element. If no such ancestor is found, the loop incorrectly continues until it reaches the XML document node (xmlDoc). Because xmlDoc lacks a namespace (ns) property, the function misinterprets integer fields (compression and standalone) as a namespace pointer. This results in an out-of-bounds memory read and a potential segmentation fault. The vulnerability can be triggered remotely if an application processes an untrusted XSL stylesheet. A fix is available in libxslt version 1.1.44 and later.
Affected products
- GNOME libxslt < 1.1.44
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat OpenShift Container Platform 4
Timeline
- 2025-10-14: disclosed: Vulnerability reported by Google Big Sleep and tracked by Red Hat.
- 2025-10-14: advisory: Initial CVE publication.
- 2026-04-27: patched: Red Hat released security updates for Hardened Images.
References
- https://gitlab.gnome.org/GNOME/libxslt
- https://catalog.redhat.com/software/containers/
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/errata/RHSA-2026:11015
- https://access.redhat.com/security/cve/CVE-2025-11731
- https://bugzilla.redhat.com/show_bug.cgi?id=2403688
- https://gitlab.gnome.org/GNOME/libxslt/-/issues/151