RHSA-2025:4098: Important: libxslt security update
Important: libxslt security update
Other sources
libxslt is a library for transforming XML files into other textual formats (including HTML, plain text, and other XML representations of the underlying data) using the standard XSLT stylesheet transformation mechanism. Security Fix(es): libxslt: Use-After-Free in libxslt numbers.c (CVE-2025-24855) libxslt: Use-After-Free in libxslt (xsltGetInheritedNsList) (CVE-2024-55549) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:4098?
The severity of RHSA-2025:4098 is rated as important.
How do I fix RHSA-2025:4098?
To fix RHSA-2025:4098, update the libxslt package to version 1.1.28-9.el7_9.
Which packages are affected by RHSA-2025:4098?
The affected packages include libxslt, libxslt-debuginfo, libxslt-devel, and libxslt-python in specified versions.
What influences the urgency of addressing RHSA-2025:4098?
Addressing RHSA-2025:4098 is urgent due to its importance level and potential vulnerabilities within the libxslt library.
Is there a known impact for users of affected software in RHSA-2025:4098?
Yes, users of affected software may experience security vulnerabilities that could be exploited.