libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
References
| Link | Resource |
|---|---|
| https://gitlab.gnome.org/GNOME/libxml2/-/issues/828 | Issue Tracking |
| https://security.netapp.com/advisory/ntap-20250328-0010/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
|
History
16 Oct 2025, 19:39
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Netapp active Iq Unified Manager
Netapp h500s Netapp h410c Firmware Netapp h410c Netapp h500s Firmware Netapp h700s Firmware Netapp manageability Software Development Kit Xmlsoft Xmlsoft libxml2 Netapp solidfire \& Hci Management Node Netapp Netapp h410s Netapp h700s Netapp h300s Firmware Netapp h300s Netapp h410s Firmware Netapp hci Compute Node Netapp ontap |
|
| References | () https://gitlab.gnome.org/GNOME/libxml2/-/issues/828 - Issue Tracking | |
| References | () https://security.netapp.com/advisory/ntap-20250328-0010/ - Third Party Advisory | |
| CPE | cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:manageability_software_development_kit:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:* cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:* cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:* |
28 Mar 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| References |
|
18 Feb 2025, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-416 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
18 Feb 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-02-18 22:15
Updated : 2025-10-16 19:39
NVD link : CVE-2024-56171
Mitre link : CVE-2024-56171
CVE.ORG link : CVE-2024-56171
JSON object : View
Products Affected
netapp
- h500s_firmware
- active_iq_unified_manager
- h410c
- h410c_firmware
- h300s_firmware
- hci_compute_node
- h700s_firmware
- h410s
- h500s
- h700s
- manageability_software_development_kit
- h300s
- solidfire_\&_hci_management_node
- h410s_firmware
- ontap
xmlsoft
- libxml2
CWE
CWE-416
Use After Free
