Skip to content

CVE-2026-9947 on CTRL-OS 26.05

Aliases: CVE-2026-9947

Packages: libxslt

Status: Acknowledged

Advisory Information

Use after free in XML in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Updates

2026-07-15 22:06 CEST

Metadata changes:

  • Status for package libxslt: “Acknowledged

2026-07-15 19:28 CEST

Metadata changes:

  • Status for package libxslt: “New

Comment:

The CVE, while being filed against Chromium, is for their bundled libxslt.

  • https://gitlab.gnome.org/GNOME/libxslt/-/work_items/171
  • https://github.com/chromium/chromium/commit/cd30fc3317627618d206710777b7e9909d171af7
  • https://chromium.googlesource.com/chromium/src/+/cd30fc3317627618d206710777b7e9909d171af7%5E%21/

(Amended on: 2026-07-15 19:35 CEST)