Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian Advisory DSA-5979-1 Addresses libxslt Critical Info Disclosure Issue

debian
Calendar Grey August 19, 2025
Debian Logo
Analyze major vulnerabilities in libxslt that result in information leakage and potential Denial of Service attacks. Users on Debian systems are advised to perform an upgrade.
Two vunlerabilities were found in libxslt, the XSLT 1.0 processing library, which may lead to information disclosure and DoS attack

Summary

CVE-2023-40403

Information disclosure with weak memory handling of generated-id()

CVE-2025-7424

Type confusion in xmlNode.psvi between stylesheet and source nodes,
which may allow an attacker to crash the application or corrupt memory.

For the oldstable distribution (bookworm), these problems have been fixed
in version 1.1.35-1+deb12u2.

For the stable distribution (trixie), these problems have been fixed in
version 1.1.35-1.2+deb13u1.

We recommend that you upgrade your libxslt packages.

For the detailed security status of libxslt please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libxslt

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: libxslt
CVE ID: CVE-2023-40403 CVE-2025-7424

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here