Msrc Cbl2 Libxslt 1.1.34-9 On Cbl Mariner 2.0 vulnerabilities

4 known vulnerabilities affecting msrc/cbl2_libxslt_1.1.34-9_on_cbl_mariner_2.0.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1LOW1

Vulnerabilities

Page 1 of 1
CVE-2025-11731LOWCVSS 3.12025-10-14
CVE-2025-11731 [LOW] CWE-843 Libxslt: type confusion in exsltfuncresultcompfunction of libxslt Libxslt: type confusion in exsltfuncresultcompfunction of libxslt Mariner: Mariner redhat: redhat Customer Action Required: Yes Remediation: CBL-Mariner Releases Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
msrc
CVE-2025-10911MEDIUMCVSS 5.52025-09-09
CVE-2025-10911 [MEDIUM] CWE-825 Libxslt: use-after-free with key data stored cross-rvt Libxslt: use-after-free with key data stored cross-rvt FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which t
msrc
CVE-2025-7424HIGHCVSS 7.32025-07-08
CVE-2025-7424 [HIGH] CWE-843 Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of
msrc
CVE-2025-7425HIGHCVSS 7.32025-07-08
CVE-2025-7425 [HIGH] CWE-416 Libxslt: heap use-after-free in libxslt caused by atype corruption in xmlattrptr Libxslt: heap use-after-free in libxslt caused by atype corruption in xmlattrptr FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure v
msrc