CVE-2024-56171

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

Configuration 8 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
cpe:2.3:a:netapp:manageability_software_development_kit:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*

History

03 Nov 2025, 21:17

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Apr/10 -
  • () http://seclists.org/fulldisclosure/2025/Apr/11 -
  • () http://seclists.org/fulldisclosure/2025/Apr/12 -
  • () http://seclists.org/fulldisclosure/2025/Apr/4 -
  • () http://seclists.org/fulldisclosure/2025/Apr/5 -
  • () http://seclists.org/fulldisclosure/2025/Apr/8 -
  • () http://seclists.org/fulldisclosure/2025/Apr/9 -
  • () https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html -

03 Nov 2025, 20:16

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Apr/13 -

16 Oct 2025, 19:39

Type Values Removed Values Added
First Time Netapp h500s Firmware
Netapp
Netapp manageability Software Development Kit
Netapp solidfire \& Hci Management Node
Netapp h410s Firmware
Netapp hci Compute Node
Netapp h700s Firmware
Netapp h410c
Netapp h500s
Xmlsoft libxml2
Netapp h300s
Xmlsoft
Netapp h300s Firmware
Netapp h410s
Netapp active Iq Unified Manager
Netapp h410c Firmware
Netapp ontap
Netapp h700s
References () https://gitlab.gnome.org/GNOME/libxml2/-/issues/828 - () https://gitlab.gnome.org/GNOME/libxml2/-/issues/828 - Issue Tracking
References () https://security.netapp.com/advisory/ntap-20250328-0010/ - () https://security.netapp.com/advisory/ntap-20250328-0010/ - Third Party Advisory
CPE cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:manageability_software_development_kit:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:*

28 Mar 2025, 15:15

Type Values Removed Values Added
Summary
  • (es) libxml2 antes de 2.12.10 y 2.13.x antes de 2.13.6 tiene un use-after-free en xmlschemaidcfillNodetable y xmlschemabubbleIdcnodetable en xmlschemas.c. Para explotar esto, un documento XML manipulado debe validarse contra un esquema XML con ciertas restricciones de identidad manipulado El esquema XML manipulado debe usarse.
References
  • () https://security.netapp.com/advisory/ntap-20250328-0010/ -

18 Feb 2025, 23:15

Type Values Removed Values Added
CWE CWE-416
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

18 Feb 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-18 22:15

Updated : 2025-11-03 21:17


NVD link : CVE-2024-56171

Mitre link : CVE-2024-56171

CVE.ORG link : CVE-2024-56171


JSON object : View

Products Affected

netapp

  • h700s_firmware
  • solidfire_\&_hci_management_node
  • h300s
  • hci_compute_node
  • ontap
  • h700s
  • h410s
  • h500s_firmware
  • h410s_firmware
  • active_iq_unified_manager
  • h300s_firmware
  • manageability_software_development_kit
  • h410c_firmware
  • h410c
  • h500s

xmlsoft

  • libxml2
CWE
CWE-416

Use After Free