Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 561
Alerts This Week
Warning Icon 1 561

Debian 11: libxslt Important DoS & Info Disclosure Issue DLA-4309-1

debian lts
Calendar Grey September 25, 2025
Scroller Debian Lts
Multiple weaknesses identified in libxslt may result in service disruption or unauthorized data exposure. An update is advised for Debian-based installations.
Two vulnerabilities were found in libxslt, an XSLT 1.0 processing library, which could lead to to denial of service or information disclosure

Summary

CVE-2023-40403

It was discovered that the generate-id() function could return
deterministic values and could leak the memory layout of different
XML objects, which might lead to information disclosure.

CVE-2025-7424

Ivan Fratric discovered a type confusion vulnerability in
xmlNode.psvi between stylesheet and source nodes. which could lead
to application crash.

For Debian 11 bullseye, these problems have been fixed in version
1.1.34-4+deb11u3.

We recommend that you upgrade your libxslt packages.

For the detailed security status of libxslt please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libxslt

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
important
Lowest
Low
Medium
High
Critical

Package: libxslt
Version: 1.1.34-4+deb11u3
CVE ID: CVE-2023-40403 CVE-2025-7424
Debian Bug: 1108074 1109123

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.