CVE-2024-55549: libxslt security updates
Accessibility. An authentication issue was addressed with improved state management.
Other sources
AirPlay. A null pointer dereference was addressed with improved input validation.
— Apple
AirPlay. A type confusion issue was addressed with improved checks.
— Apple
AirPlay. An input validation issue was addressed.
— Apple
AirPlay. The issue was addressed with improved memory handling.
— Apple
AppKit. The issue was addressed with additional permissions checks.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libxsltto a version that resolves this vulnerability.Fixed in 1.1.34-4+deb11u2Fixed in 1.1.35-1+deb12u1Fixed in 1.1.35-1.2 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 18.3 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 2.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 11.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 17.7.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.2.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.7.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.7.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.3 - Upgrade
Upgrade
libxsltto a version that resolves this vulnerability.Fixed in 1.1.43 - Operational
Ensure systems use libxslt 1.1.43 or later, since libxslt versions before 1.1.43 contain use-after-free vulnerabilities in functions including xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal (related to issues in xsltGetInheritedNsList) that can be triggered via nested XPath evaluations.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-24179
- CVE-2025-24126
- CVE-2025-24129
- CVE-2025-24131
- CVE-2025-24137
- CVE-2025-24127
- CVE-2025-24160
- CVE-2025-24161
- CVE-2025-24163
- CVE-2025-24123
- CVE-2025-24124
- CVE-2025-24085
- CVE-2025-24184
- CVE-2025-24111
- CVE-2025-24086
- CVE-2025-24144
- CVE-2025-24107
- CVE-2025-24159
- CVE-2024-55549
- CVE-2025-24855
- CVE-2025-31262
- CVE-2025-24149
- CVE-2025-24189
- CVE-2025-24158
- CVE-2025-24162
- CVE-2025-24117
- CVE-2025-24113
- CVE-2025-24154
- CVE-2025-24143
- CVE-2025-24102
- CVE-2024-54478
- CVE-2025-24118
- CVE-2025-24104
- CVE-2024-54497
- CVE-2025-24177
- CVE-2025-24087
- CVE-2025-24112
- CVE-2025-24100
- CVE-2025-24109
- CVE-2025-24114
- CVE-2025-24121
- CVE-2025-24122
- CVE-2025-24106
- CVE-2025-24134
- CVE-2025-24140
- CVE-2025-24174
- CVE-2025-24119
- CVE-2025-24094
- CVE-2025-24115
- CVE-2025-24116
- CVE-2025-24136
- CVE-2025-24101
- CVE-2025-24096
- CVE-2025-24099
- CVE-2025-24130
- CVE-2025-24169
- CVE-2025-24183
- CVE-2025-24146
- CVE-2025-24128
- CVE-2025-24103
- CVE-2025-24108
- CVE-2025-24185
- CVE-2025-24139
- CVE-2025-24151
- CVE-2025-24152
- CVE-2025-24153
- CVE-2025-24138
- CVE-2025-24176
- CVE-2025-24135
- CVE-2025-24145
- CVE-2025-24092
- CVE-2025-24155
- CVE-2025-24150
- CVE-2025-24120
- CVE-2025-24156
- CVE-2024-44172
- CVE-2025-24093
- CVE-2025-31242
- CVE-2025-31248
- CVE-2025-43374
- CVE-2024-54509
- CVE-2024-44243
- CVE-2025-24141
- CVE-2025-24089
- CVE-2025-24090
- CVE-2025-24091
- CVE-2024-9956
- CVE-2025-31185
- CVE-2025-11224
- CVE-2025-11865
- CVE-2025-2615
- CVE-2025-7000
- CVE-2025-6945
- CVE-2025-11990
- CVE-2025-6171
- CVE-2025-7736
- CVE-2025-12983
Frequently Asked Questions
What is the severity of CVE-2024-55549?
CVE-2024-55549 has been classified as a high-severity vulnerability due to the potential for exploitation through a use-after-free condition.
How do I fix CVE-2024-55549?
To fix CVE-2024-55549, upgrade libxslt to version 1.1.43 or later as it addresses this vulnerability.
What versions of libxslt are affected by CVE-2024-55549?
CVE-2024-55549 affects all versions of libxslt prior to 1.1.43.
What is a use-after-free issue in the context of CVE-2024-55549?
In the context of CVE-2024-55549, a use-after-free issue occurs when the software attempts to access memory after it has been freed, leading to potential vulnerabilities.
Can CVE-2024-55549 lead to remote code execution?
Yes, if exploited, CVE-2024-55549 may allow attackers to execute arbitrary code on affected systems.