Fiche vulnérabilité
CVE-2024-56171 : faille critique xmlsoft libxml2 (CVSS 9.8)
Description
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 18 févr. 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- xmlsoft libxml2
- netapp hci compute node
- netapp h410c firmware
- netapp h300s firmware
- netapp h500s firmware
- netapp h700s firmware
- netapp h410s firmware
- netapp active iq unified manager
- netapp manageability software development kit
- netapp ontap
- netapp solidfire \& hci management node
Références
- Fiche CVE-2024-56171 sur le NVD (NIST)
- gitlab.gnome.org/GNOME/libxml2/-/issues/828
- seclists.org/fulldisclosure/2025/Apr/10
- seclists.org/fulldisclosure/2025/Apr/11
- seclists.org/fulldisclosure/2025/Apr/12
- seclists.org/fulldisclosure/2025/Apr/13
- seclists.org/fulldisclosure/2025/Apr/4
- seclists.org/fulldisclosure/2025/Apr/5
- seclists.org/fulldisclosure/2025/Apr/8
- seclists.org/fulldisclosure/2025/Apr/9
- lists.debian.org/debian-lts-announce/2025/02/msg00028.html
- security.netapp.com/advisory/ntap-20250328-0010/