Use-After-Free Vulnerability in libxslt Affecting GNOME Products
CVE-2025-10911

5.5MEDIUM

What is CVE-2025-10911?

A use-after-free vulnerability was discovered in libxslt, which occurs while parsing XSL nodes. This flaw can lead to the dereference of expired pointers, potentially resulting in application crashes. It highlights a critical area for improvement in handling memory management within the library to ensure robust and secure functionality.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-10911 : Use-After-Free Vulnerability in libxslt Affecting GNOME Products