libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
|
History
03 Nov 2025, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Information
Published : 2025-02-18 22:15
Updated : 2025-11-03 21:17
NVD link : CVE-2024-56171
Mitre link : CVE-2024-56171
CVE.ORG link : CVE-2024-56171
JSON object : View
Products Affected
netapp
- h300s
- h300s_firmware
- ontap
- solidfire_\&_hci_management_node
- h410c_firmware
- hci_compute_node
- h500s
- h700s_firmware
- h410s
- h700s
- h410c
- h410s_firmware
- manageability_software_development_kit
- h500s_firmware
- active_iq_unified_manager
xmlsoft
- libxml2
CWE
CWE-416
Use After Free
