libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.
References
| Link | Resource |
|---|---|
| https://gitlab.gnome.org/GNOME/libxml2/-/issues/847 | Issue Tracking |
| https://issues.oss-fuzz.com/issues/392687022 | Issue Tracking |
| https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html | |
| https://security.netapp.com/advisory/ntap-20250321-0006/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
History
03 Nov 2025, 22:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Information
Published : 2025-02-18 23:15
Updated : 2025-11-03 22:18
NVD link : CVE-2025-24928
Mitre link : CVE-2025-24928
CVE.ORG link : CVE-2025-24928
JSON object : View
Products Affected
netapp
- h300s
- h300s_firmware
- ontap
- h410c_firmware
- hci_compute_node
- h500s
- h700s_firmware
- h410s_firmware
- h410s
- h700s
- h410c
- solidfire_\&_hci_management_node
- manageability_software_development_kit
- h500s_firmware
- active_iq_unified_manager
xmlsoft
- libxml2
CWE
CWE-121
Stack-based Buffer Overflow
