CVE-2025-10911

Red Hat Security Advisory: Red Hat Update Infrastructure 5.3 Technology Preview security update

mediumEPSS 0.2%

Description

A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.

Metrics

Severity
medium
no public PoC known
5.5
Source: nvd-v3
6.8 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-24 11:15 UTC
CWE-825

Weakness classes (CWE)

  • CWE-825Base

    Expired Pointer Dereference

    The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-31 15:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/10xxx/CVE-2025-10911.json">CVE-2025-10911</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:11015
    • Reference: https://access.redhat.com/errata/RHSA-2026:26355
    • Reference: https://access.redhat.com/errata/RHSA-2026:28243
  2. CVE Modified2026-08-21 13:16 UTC· secalert@redhat.com
    • Affected: …, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+18)…, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+18)
  3. CVE Modified2026-07-23 14:16 UTC· secalert@redhat.com
    • Reference: https://access.redhat.com/errata/RHSA-2026:44481
    • Affected: …, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+17)…, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+18)
  4. CVE Modified2026-06-25 16:16 UTC· secalert@redhat.com
    • Reference: https://access.redhat.com/errata/RHSA-2026:29975
    • Affected: …, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+10)…, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+12)
  5. CVE Modified2026-06-24 07:16 UTC· secalert@redhat.com
    • Reference: https://access.redhat.com/errata/RHSA-2026:28584
    • Affected: …, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8 (+6)…, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 (+6)

Affected operating systems

  • linux

    ubuntu / coreutilsjammy

  • linux

    ubuntu / coreutilsnoble

  • linux

    ubuntu / coreutilsresolute

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux10.2

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux9.8

  • linux

    redhat / enterprise_linux_for_els10.2

  • linux

    redhat / enterprise_linux_for_els8.10

  • linux

    redhat / enterprise_linux_for_els9.8

  • linux

    redhat / enterprise_linux_for_eus10.2

  • linux

    redhat / enterprise_linux_for_eus9.8

  • linux

    redhat / enterprise_linux_for_ibm_z_systems10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems8.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems9.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els8.10

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els9.8

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus9.8

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • Apple

    iOS18.7.10

  • Apple

    iOS26.6.1

  • Apple

    iPadOS18.7.10

  • Apple

    iPadOS26.6.1

  • Apple

    macOSTahoe 26.6.2

  • bitnami

    jre1.9.0

  • bitnami

    nginx-gateway0.1.17

  • bitnami

    nginx-gateway-fabric1.3.0

  • bitnami

    postgresql15.0.0

  • bitnami

    postgresql16.0.0

  • bitnami

    postgresql17.0.0

  • bitnami

    postgresql18.0.0

  • bitnami

    python-min3.10.0

  • bitnami

    python-min3.11.0

  • bitnami

    python-min3.12.0

  • bitnami

    python-min3.13.0

  • bitnami

    python-min3.14.0

  • f5

    dos4.3.0 – 4.7.0

  • f5

    dos

  • f5

    nginx_gateway_fabric1.3.0 – 1.6.2

  • f5

    nginx_gateway_fabric2.0.0 – 2.5.1

  • f5

    nginx_ingress_controller3.5.0 – 3.7.2

  • f5

    nginx_ingress_controller4.0.0 – 4.0.1

  • f5

    nginx_ingress_controller5.0.0 – 5.4.1

References & sources

Linked CVEs

Show 93 more CVEs
IDCVE-2025-10911