numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:3107 https://access.redhat.com/errata/RHSA-2025:3107
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:3389 https://access.redhat.com/errata/RHSA-2025:3389
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2025:3528 https://access.redhat.com/errata/RHSA-2025:3528
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:3612 https://access.redhat.com/errata/RHSA-2025:3612
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:3615 https://access.redhat.com/errata/RHSA-2025:3615
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:3619 https://access.redhat.com/errata/RHSA-2025:3619
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat Enterprise Linux 8.4 Telecommunications Update Service Via RHSA-2025:3626 https://access.redhat.com/errata/RHSA-2025:3626
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:3625 https://access.redhat.com/errata/RHSA-2025:3625
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2025:3624 https://access.redhat.com/errata/RHSA-2025:3624
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:3627 https://access.redhat.com/errata/RHSA-2025:3627
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:4098 https://access.redhat.com/errata/RHSA-2025:4098
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2025:4422 https://access.redhat.com/errata/RHSA-2025:4422
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2025:4427 https://access.redhat.com/errata/RHSA-2025:4427
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:4431 https://access.redhat.com/errata/RHSA-2025:4431
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:7496 https://access.redhat.com/errata/RHSA-2025:7496
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2025:4731 https://access.redhat.com/errata/RHSA-2025:4731
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2025:4677 https://access.redhat.com/errata/RHSA-2025:4677