Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2024-56171: XML library can be tricked into crashing
CVE-2024-56171 · published today
Summary
The libxml2 component used in several NetApp and Alpine Linux products can be made to fail, potentially disrupting services. This occurs when specially crafted XML data is processed. Apply the latest updates for the listed products to protect your systems.
What to do
- Update libxml2 to version 2.9.14-r20071.
- Update rootio-libxml2 to version 2.9.14-r20071.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | xmlsoft | libxml2 |
< 2.12.10 >= 2.13.0, < 2.13.6 cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* |
| – | netapp | hci_compute_node |
All versions
cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:* |
| – | netapp | h410c_firmware |
All versions
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:* |
| – | netapp | h300s_firmware |
All versions
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* |
| – | netapp | h500s_firmware |
All versions
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* |
| – | netapp | h700s_firmware |
All versions
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* |
| – | netapp | h410s_firmware |
All versions
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:* |
| – | netapp | active_iq_unified_manager |
All versions
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:* |
| – | netapp | manageability_software_development_kit |
All versions
cpe:2.3:a:netapp:manageability_software_development_kit:-:*:*:*:*:*:*:* |
| – | netapp | ontap |
9 cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:* |
| – | netapp | solidfire_\&_hci_management_node |
All versions
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:* |
| Root:Alpine:3.15 | – | libxml2 |
< 2.9.14-r20071 Fix: upgrade to 2.9.14-r20071
|
| Root:Alpine:3.15 | – | rootio-libxml2 |
< 2.9.14-r20071 Fix: upgrade to 2.9.14-r20071
|
Original advisory text
CVE-2024-56171 in libxml2 - Patched by Root
Root has patched CVE-2024-56171 in the libxml2 package for Root:Alpine:3.15. Multiple fixed versions available.
References
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/828 Issue Tracking
- http://seclists.org/fulldisclosure/2025/Apr/10
- http://seclists.org/fulldisclosure/2025/Apr/11
- http://seclists.org/fulldisclosure/2025/Apr/12
- http://seclists.org/fulldisclosure/2025/Apr/13
- http://seclists.org/fulldisclosure/2025/Apr/4
- http://seclists.org/fulldisclosure/2025/Apr/5
- http://seclists.org/fulldisclosure/2025/Apr/8
- http://seclists.org/fulldisclosure/2025/Apr/9
- https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html
- https://security.netapp.com/advisory/ntap-20250328-0010/ Third Party Advisory
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS 1%
Type
CWE-416Use After Free
Timeline
Published25 Sep 2026
Updated25 Sep 2026
First seen7 Mar 2026
Track software like this
Free during beta