Skip to main content
News Directory 3
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Menu
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World

Libxslt Vulnerabilities: Unmaintained and Unfixed Security Risks

August 29, 2025 Lisa Park Tech
News Context
At a glance
  • Security⁢ vulnerabilities have been identified in libxml2 and libxslt, with ⁢two of three reported issues in libxslt now publicly disclosed.
  • (CVE-2025-7424) concerns⁣ a type confusion vulnerability in libxslt affecting ‍the interaction between stylesheet and source nodes within the xmlNode.psvi function.
  • (CVE-2025-7425) details a heap-use-after-free vulnerability in libxslt's xmlFreeID function, triggered by corruption of the atype variable.
Original source: vuxml.freebsd.org

Libxslt Vulnerabilities Disclosed: Patches Await Maintainer

Table of Contents

  • Libxslt Vulnerabilities Disclosed: Patches Await Maintainer
    • Overview
    • Vulnerability Details
    • Patch Status and Maintainership
    • Impact and affected Systems

July 11, 2025 – Updated August 29, 2025, ‍07:27:16 ⁤UTC

Overview

Security⁢ vulnerabilities have been identified in libxml2 and libxslt, with ⁢two of three reported issues in libxslt now publicly disclosed. These vulnerabilities, ‍discovered by engineers at Apple and Google, currently lack applied patches due to the absence of a maintainer for the libxslt project.

Vulnerability Details

(CVE-2025-7424) concerns⁣ a type confusion vulnerability in libxslt affecting ‍the interaction between stylesheet and source nodes within the xmlNode.psvi function. ⁢ Further information is available on the GNOME GitLab issue tracker and Project ZeroS issue tracker.

(CVE-2025-7425) details a heap-use-after-free vulnerability in libxslt’s xmlFreeID function, triggered by corruption of the atype variable. Details can be found on the GNOME GitLab issue tracker ⁤ and project Zero’s issue tracker.

Patch Status and Maintainership

While Apple and Google engineers have ⁤submitted proposed patches to the⁣ GNOME GitLab repository, these fixes have not been applied. This is directly attributable to the current lack ⁢of a maintainer for the libxslt project, preventing the integration of these critical security updates.

Impact and affected Systems

The impact of these vulnerabilities is currently being assessed. Systems utilizing libxslt are potentially at risk. ‍Users are advised to monitor the GNOME Security Wiki for ⁤updates and potential workarounds.

Source: Openwall OSS Security mailing list

This article was last updated on August 29, 2025, at 07:27:16 UTC to provide the latest information available.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

Keep reading

  • YouTube Ad Revenue Surges While User Data Costs Remain Hidden
  • Australia Digital Duty Targets Design Not Content Says Creator
  • Why the Social Security COLA Is Announced in October (daybreakwire.com)
  • AZDOHS outlines Nonprofit Security Grant Program deadlines (archynewsy.com)

Related

Search:

News Directory 3

News Directory 3 catalogs US newspapers, news services, newsstands and digital news outlets across all 50 states. Browse local publishers by city, state, or topic, and follow current headlines linked back to their original sources.

Quick Links

  • Disclaimer
  • Terms and Conditions
  • About Us
  • Advertising Policy
  • Contact Us
  • Cookie Policy
  • Editorial Guidelines
  • Privacy Policy

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

© 2026 News Directory 3. All rights reserved.
For contact, advertising, copyright, issues email: office@newsdirectory3.com