REDHAT-BUG-2403688: Low severity libxslt libxslt vulnerability

Published Oct 14, 2025
·
Updated

Type Confusion vulnerability in the EXSLT <func:result> element handler of libxslt. The flaw resides in the exsltFuncResultComp() function, which walks up the node hierarchy to verify that a <func:result> is a descendant of a func:function element. If no such ancestor exists, the loop continues until the XML document node is reached, where the ns pointer is incorrectly interpreted as integer fields (compression and standalone). This type confusion results in reading memory from an unexpected address, leading to a segmentation fault or crash. Although the impact is limited to denial-of-service, the issue can be triggered remotely by processing malicious XSL stylesheets.

Affected Software

1 affected component
libxslt libxslt

Event History

Oct 14, 2025
Data Sourced
via Red Hat·05:31 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2403688?

The severity of REDHAT-BUG-2403688 is classified as critical due to its potential for type confusion vulnerabilities in libxslt.

2

How do I fix REDHAT-BUG-2403688?

To fix REDHAT-BUG-2403688, update your libxslt package to the latest version provided by your distribution.

3

What poses the risk in REDHAT-BUG-2403688?

The risk in REDHAT-BUG-2403688 lies in the flaw in the exsltFuncResultComp() function which can lead to arbitrary code execution.

4

Which software is affected by REDHAT-BUG-2403688?

The software affected by REDHAT-BUG-2403688 is the libxslt library.

5

What is the nature of the vulnerability in REDHAT-BUG-2403688?

The nature of the vulnerability in REDHAT-BUG-2403688 is a type confusion issue in the handling of the <func:result> element.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203