USN-7945-1: Libxslt vulnerability

Publication date

7 January 2026

Overview

Libxslt could be made to crash or exhibit undefined behavior if it opened a specially crafted file.


Packages

  • libxslt - XSLT processing library

Details

Ivan Fratric discovered that Libxslt was vulnerable to type confusion when
performing XML transformations. An attacker could possibly use this issue
to cause Libxslt to crash or corrupt memory, causing a denial of service or
undefined behavior.

Ivan Fratric discovered that Libxslt was vulnerable to type confusion when
performing XML transformations. An attacker could possibly use this issue
to cause Libxslt to crash or corrupt memory, causing a denial of service or
undefined behavior.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
25.04 plucky libxslt1.1 –  1.1.39-0exp1ubuntu4.1
xsltproc –  1.1.39-0exp1ubuntu4.1
24.04 LTS noble libxslt1.1 –  1.1.39-0exp1ubuntu0.24.04.3
xsltproc –  1.1.39-0exp1ubuntu0.24.04.3
22.04 LTS jammy libxslt1.1 –  1.1.34-4ubuntu0.22.04.5
xsltproc –  1.1.34-4ubuntu0.22.04.5
20.04 LTS focal libxslt1.1 –  1.1.34-4ubuntu0.20.04.3+esm2  
xsltproc –  1.1.34-4ubuntu0.20.04.3+esm2  
18.04 LTS bionic libxslt1.1 –  1.1.29-5ubuntu0.3+esm3  
xsltproc –  1.1.29-5ubuntu0.3+esm3  
16.04 LTS xenial libxslt1.1 –  1.1.28-2.1ubuntu0.3+esm4  
xsltproc –  1.1.28-2.1ubuntu0.3+esm4  
14.04 LTS trusty libxslt1.1 –  1.1.28-2ubuntu0.2+esm5  
xsltproc –  1.1.28-2ubuntu0.2+esm5  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›