Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2024-56171: XML library can be tricked into crashing

CVE-2024-56171 · published today
Summary

The libxml2 component used in several NetApp and Alpine Linux products can be made to fail, potentially disrupting services. This occurs when specially crafted XML data is processed. Apply the latest updates for the listed products to protect your systems.

What to do
  • Update libxml2 to version 2.9.14-r20071.
  • Update rootio-libxml2 to version 2.9.14-r20071.
Affected software
Ecosystem VendorProductAffected versions
– xmlsoft libxml2 < 2.12.10
>= 2.13.0, < 2.13.6
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
– netapp hci_compute_node All versions
cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*
– netapp h410c_firmware All versions
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
– netapp h300s_firmware All versions
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
– netapp h500s_firmware All versions
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
– netapp h700s_firmware All versions
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
– netapp h410s_firmware All versions
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
– netapp active_iq_unified_manager All versions
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
– netapp manageability_software_development_kit All versions
cpe:2.3:a:netapp:manageability_software_development_kit:-:*:*:*:*:*:*:*
– netapp ontap 9
cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:*
– netapp solidfire_\&_hci_management_node All versions
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
Root:Alpine:3.15 – libxml2 < 2.9.14-r20071
Fix: upgrade to 2.9.14-r20071
Root:Alpine:3.15 – rootio-libxml2 < 2.9.14-r20071
Fix: upgrade to 2.9.14-r20071
Original advisory text
CVE-2024-56171 in libxml2 - Patched by Root
Root has patched CVE-2024-56171 in the libxml2 package for Root:Alpine:3.15. Multiple fixed versions available.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS 1%
Type
CWE-416Use After Free
Timeline
Published25 Sep 2026
Updated25 Sep 2026
First seen7 Mar 2026
Track software like this
Free during beta