CVE-2017-5029: Debian Linux

High severity, CVSS 8.8. EPSS: 2.2% chance of exploitation in the next 30 days.

The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Google Chrome: up to and including 57.0.2987.75; up to and including 57.0.2987.100
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only
  • Xmlsoft Libxslt: version 1.1.29 only

Published 2017-04-24. Last modified 2026-06-17.