CVE-2024-56171: Use After Free
Published Feb 18, 2025
·Updated
Accessibility. A logging issue was addressed with improved data redaction.
Credit
Anonymous(Trend Micro Zero Day Initiative), Wang Yu(Cyberserval), Michael (Biscuit) Thomas - @social.lol@@biscuit, CVE-2024-48958, an anonymous researcher, CVE-2025-27113, CVE-2024-56171, Alex Radocea(Supernetworks), Dave G.(Supernetworks), 风沐云烟@@binary_fmyy, Minghao Lin@@Y1nKoc, Jonathan Bar Or@@yo_yo_yo_jbo(Microsoft), Alexia Wilson(Microsoft), Christine Fossaceca(Microsoft), LFY@@secsys(Fudan University), Jimmy, Mickey Jin@@patch1t, Jaydev Ahire, @@RenwaX23, Bing Shi(Alibaba Group), Wenchao Li(Alibaba Group), Xiaolong Bai(Alibaba Group), Luyi Xing(Indiana University Bloomington), Halle Winkler, Politepix theoffcuts.org, Andrew James Gonzalez, Kirin@@Pwnrin, Alexander Heinrich@@Sn0wfreeze, SEEMOO, TU Darmstadt & Mathy Vanhoef@@vanhoefm, Jeroen Robben@@RobbenJeroen, DistriNet, KU Leuven, Vsevolod Kokorin (Slonser)(Solidlab), Gary Kwong, Paul Bakker(ParagonERP), rheza@@ginggilBesel, Yutong Xiu@@Sou1gh0st, Denis Tokarev@@illusionofcha0s, Google Threat Analysis Group, Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), wac(Trend Micro Zero Day Initiative), Uri Katz (Oligo Security), CVE-2024-9681, Andr.Ess, Dominik Rath, Martin Kreichgauer(Google Chrome), Lehan Dilusha@@zafer, Wojciech Regula(SecuRing), Claudio Bozzato(Cisco Talos), Francesco Benvenuto(Cisco Talos), Bohdan Stasiuk@@bohdan_stasiuk, CVE-2025-24085, YingQi Shi@@Mas0nShi(DBAppSecurity's WeBin lab), Stephan Casas, Csaba Fitzl@@theevilbit(Kandji), Gergely Kalman@@gergely_kalman, Rodolphe BRUNETTI@@eisw0lf(Lupus Nova), Pietro Francesco Tirenna(Shielder), Davide Silvetti(Shielder), Abdel Adim Oisfi(Shielder), Manuel Fernandez (Stackhopper Security), Murray Mike(Trend Micro Zero Day Initiative), ABC Research s.r.o., Ian Beer(Google Project Zero), Kenneth Chew, Paweł Płatek (Trail(Bits), 风沐云烟@@binary_fmyy(Supernetworks), Minghao Lin@@Y1nKoc(Supernetworks), Diamant Osmani & Valdrin Haliti [Kosovë], dbpeppe, Solitechworld, Pwn2car, Mickey Jin@@patch1t(Kandji), (Kandji), Pedro Tôrres@@t0rr3sp3dr0, Noah Gregory (wts.dev), Arsenii Kostromin (0x3c3e), Dolf Hoegaerts, Michiel Devliegere, Junsung <3(Trend Micro Zero Day Initiative), Richard Hyunho Im with routezero.security@@richeeta, Joseph Ravichandran@@0xjprx(MIT CSAIL), zbleet(QI), Csaba Fitzl@@theevilbit(OffSec), 风沐云烟 (binary_fmyy)(DBAppSecurity's WeBin lab), Minghao Lin@@Y1nKoc(DBAppSecurity's WeBin lab), Zhongquan Li@@Guluisacat, PixiePoint Security, Andreas Hegenberg (folivora.AI GmbH), Francisco Alonso@@revskills, pattern-f@@pattern_F_, Ron Masas(BREAKPOINT), mzzzz__, Muhammad Zaid Ghifari (Mr.ZheeV), Kalimantan Utara, Florian Draschbacher, Jax Reissner, Dalibor Milanovic, Syarif Muhammad Sajjad, Abhay Kailasia@@abhay_kailasia(C), Chi Yuan Chang(ZUSO ART), taikosoup, Zhongcheng Li(IES Red Team of ByteDance), Ian Mckay@@iann0036, Nolan Astrein(Kandji), luckyu@@uuulucky, Rodolphe BRUNETTI@@eisw0lf, Murray Mike, Dayton Pidhirney(Atredis Partners), Lyutoon, YenKoc, Ye Zhang@@VAR10CK(Baidu Security), Koh M. Nakagawa@@tsunek0h(FFRI Security Inc), CVE-2023-27043, Yiğit Can YILMAZ@@yilmazcanyigit, K宝@@Pwnrin, Tong Liu@@Lyutoon_, 风(binary_fmyy), F00L, Cristian Dinca(Computer Science), Romania, 风沐云烟 (binary_fmyy), Kirin, FlowerCode, Pedro José Pereira Vieito / pvieito.com)@@pvieito, Apple, Lukas Bernhard, Tashita Software Security, Xiangwei Zhang(Tencent Security YUNDING LAB), linjy(HKUS3Lab), chluo(WHUSecLab), Brendon Tiszka(Google Project Zero)
Affected Software
33 affected componentsFixes available
Gnome libxml2<2.12.10, >2.13.0<=2.13.6
debian/libxml2<=2.9.10+dfsg-6.7+deb11u4, <=2.9.14+dfsg-1.3~deb12u1, <=2.12.7+dfsg+really2.9.14-0.2, <=2.12.7+dfsg+really2.9.14-0.3
2.9.10+dfsg-6.7+deb11u6
Apple macOS Sonoma<14.7.5
14.7.5
Apple macOS Ventura<13.7.5
13.7.5
Apple iPadOS<17.7.6
17.7.6
Apple macOS Sequoia<15.4
15.4
F5 Traffix SDC=5.2.0
5.2.0
Xmlsoft Libxml2<2.12.10
Xmlsoft Libxml2>=2.13.0<2.13.6
All of the following
NetApp Hci Compute Node
NetApp Hci Compute Node
All of the following
NetApp H410c Firmware
NetApp H410c
All of the following
NetApp H300s Firmware
NetApp H300s
All of the following
NetApp H500s Firmware
NetApp H500s
All of the following
NetApp H700s Firmware
NetApp H700s
All of the following
NetApp H410s Firmware
NetApp H410s
NetApp Active Iq Unified Manager Vsphere
NetApp Manageability Software Development Kit
NetApp Ontap=9
NetApp Solidfire \& Hci Management Node
Apple visionOS<2.4
2.4
Apple tvOS<18.4
18.4
Apple WatchOS<11.4
11.4
Apple iOS<18.4
18.4
Apple iPadOS<18.4
18.4
Microsoft azl3 libxml2 2.11.5-5
Microsoft cbl2 libxml2 2.10.4-6
Microsoft azl3 libxml2 2.11.5-4
Event History
Feb 18, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
Affected Software
Data Sourced
via Red Hat·11:01 PM
DescriptionSeverityAffected Software
Feb 25, 2025
Data Sourced
via Ubuntu·11:59 PM
RemedyDescriptionSeverityAffected Software
Feb 27, 2025
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
DescriptionSeverity
Mar 14, 2025
Data Sourced
via Launchpad·12:04 AM
Description
Mar 31, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
Updated
via Apple·12:00 AM
DescriptionAffected Software
Apr 1, 2025
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Aug 8, 2025
Advisory Published
via F5·08:15 PM
Data Sourced
via F5·08:15 PM
DescriptionSeverityWeaknessAffected Software
Jan 30, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-56171?
CVE-2024-56171 has a high severity due to the potential for exploitation through crafted XML documents.
2
How do I fix CVE-2024-56171?
To fix CVE-2024-56171, upgrade libxml2 to version 2.12.10 or 2.13.6 or later.
3
What versions of libxml2 are affected by CVE-2024-56171?
CVE-2024-56171 affects libxml2 versions before 2.12.10 and 2.13.0 through 2.13.5.
4
Can CVE-2024-56171 be exploited remotely?
Yes, CVE-2024-56171 can be exploited remotely if a vulnerable version processes untrusted XML documents.
5
What types of applications are at risk from CVE-2024-56171?
Applications that use affected versions of libxml2 for XML processing and validation are at risk from CVE-2024-56171.