安全公告详情

NS-SA-2026-0092

2026-09-07 18:00:00

简介

important: libxslt/curl security update

严重级别

important

主题

An update for libxslt/curl is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

libxslt:
curl:


Security Fix(es):
libxslt: A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected memory reads and potential crashes. While difficult to exploit, the flaw could lead to application instability or denial of service.(CVE-2025-11731)
libxslt: A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.(CVE-2025-10911)
libxslt: A flaw was found in libxslt numbers.c. This vulnerability allows a use-after-free, potentially leading to memory corruption or code execution via nested XPath evaluations where an XPath context node can be modified but not restored.(CVE-2025-24855)
libxslt: A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt memory. In some cases, it may lead to denial of service or unexpected behavior.(CVE-2025-7424)
libxslt: bugfix
curl: An out of bounds read flaw has been discovered in the curl project. Under specific conditions the path comparison logic makes curl read outside a heap buffer boundary. This bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path.(CVE-2025-9086)
curl: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.07B5.

影响组件

  • libxslt
  • curl

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["python3-libxslt-1.1.43-5.zncgsl7.1.x86_64.rpm","libxslt-doc-1.1.43-5.zncgsl7.1.noarch.rpm","libxslt-1.1.43-5.zncgsl7.1.x86_64.rpm","libxslt-devel-1.1.43-5.zncgsl7.1.x86_64.rpm"],"source":"libxslt-1.1.43-5.zncgsl7.1.src.rpm"},{"binary":["libcurl-8.4.0-3.zncgsl7.18.x86_64.rpm","libcurl-minimal-8.4.0-3.zncgsl7.18.x86_64.rpm","libcurl-devel-8.4.0-3.zncgsl7.18.x86_64.rpm","curl-doc-8.4.0-3.zncgsl7.18.noarch.rpm","curl-8.4.0-3.zncgsl7.18.x86_64.rpm","curl-minimal-8.4.0-3.zncgsl7.18.x86_64.rpm"],"source":"curl-8.4.0-3.zncgsl7.18.src.rpm"}]}]}

CVE

参考