Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-56171

30
FAUCET Score

CVE-2024-56171 is a critical use-after-free vulnerability (CWE-416) in libxml2 versions prior to 2.12.10 and 2.13.6, affecting products like NetApp and xmlsoft. It carries a CVSS score of 9.8, indicating a severe risk with a network attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability compromise. While no active exploitation, public exploit code, or significant community discussion has been observed, the vulnerability's high severity warrants immediate patching.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.12.10CPE matchmatch criteria
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
>= 2.13.0, < 2.13.6CPE matchmatch criteria
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.4
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.14%
Probability of exploitation in next 30 days
EPSS Percentile
63.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0114 is in the 49th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (65)

codesyspatch availablevia llm_extracted
View patch
esphomepatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 19447-17084Fixed in: 2.11.5-4
microsoftpatch availablevia msrc
Product: 20051-17086Fixed in: 2.10.4-6
microsoftpatch availablevia msrc
Product: azl3 libxml2 2.11.5-4 on Azure Linux 3.0Fixed in: 2.11.5-4
microsoftpatch availablevia msrc
Product: cbl2 libxml2 2.10.4-6 on CBL Mariner 2.0Fixed in: 2.10.4-6
microsoftpatch availablevia msrc
Product: azl3 libxml2 2.11.5-5 on Azure Linux 3.0Fixed in: 2.11.5-4
microsoftpatch availablevia msrc
Product: 17475-17084Fixed in: 2.11.5-4
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: libxml2-0:2.9.7-13.el8_6.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: libxml2-0:2.9.7-16.el8_8.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: libxml2-0:2.9.13-6.el9_5.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: libxml2-0:2.9.13-1.el9_0.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: libxml2-0:2.9.13-3.el9_2.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: libxml2-0:2.9.13-9.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Core Services 2.4.62Fixed in: libxml2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.12Fixed in: rhcos-412.86.202503310142-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.13Fixed in: rhcos-413.92.202503112237-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.14Fixed in: rhcos-414.92.202504010153-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: rhcos-415.92.202503190057-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.16Fixed in: rhcos-416.94.202503252048-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.17Fixed in: rhcos-417.94.202503172033-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.18Fixed in: rhcos-418.94.202503181639-0
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-config-sync-rhel9:1.4.8-1
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-flow-collector-rhel9:1.4.8-1
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-operator-bundle:1.4.8-1
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-router-rhel9:2.4.3-9
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-service-controller-rhel9:1.4.8-1
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-site-controller-rhel9:1.4.8-1
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: skupper-config-sync-container-1.8.5-1
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: skupper-controller-podman-container-1.8.5-1
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: skupper-flow-collector-container-1.8.5-1
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: skupper-operator-bundle-container-1.8.5-2
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: skupper-router-container-2.7.5-2
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: skupper-service-controller-container-1.8.5-1
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: skupper-site-controller-container-1.8.5-1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.16Fixed in: rhoai/odh-data-science-pipelines-argo-argoexec-rhel8:sha256:ee01e89f98feb185f6cd59c564e590a13e4d8d9ea760cca8de51426eb71b83a1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.16Fixed in: rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel8:sha256:d7d4fa406e0fcf0507894a7676532b27f45be742467e603a86f98ea5d2615df8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.16Fixed in: rhoai/odh-data-science-pipelines-operator-controller-rhel8:sha256:a0f72ffefb2b74b488dd949493f5d295a39bb9c97f578bf219d0138601f65468
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.16Fixed in: rhoai/odh-kuberay-operator-controller-rhel8:sha256:5394cd240a8857906803affec711959da8b8da4e9a7225ddaefe9736c98949b4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.16Fixed in: rhoai/odh-kueue-controller-rhel8:sha256:036af0457f091059551ff63563d5cf68f062297a5630a869bbf3398d5e97ffdc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.16Fixed in: rhoai/odh-ml-pipelines-driver-rhel8:sha256:2257fe7947959fd59346d2b322f7dbb471831880df659e57344b0d804c2c0099
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.16Fixed in: rhoai/odh-ml-pipelines-launcher-rhel8:sha256:8783f8aaed686a63ed1f913364c85606b1447540608f5b7f45412ff0868a4f38
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.16Fixed in: rhoai/odh-kf-notebook-controller-rhel8:sha256:2ba2b2c4db8bb334c50f4dfb54059f060361186900a44c06eed00b7a3c43977e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.16Fixed in: rhoai/odh-kuberay-operator-controller-rhel8:sha256:65482864055021272a18b5b26792ab00cfa5fc9cc005d8d3a884cc82991506f3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.16Fixed in: rhoai/odh-kueue-controller-rhel8:sha256:7b70af8847b0806d8b43c399e2b3109f016fd864f5e9d30c44e2baca5d1359dc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.16Fixed in: rhoai/odh-mlmd-grpc-server-rhel8:sha256:5dcdcc2424602a69451f16d31dbfa1d43cb72c095ba561eb9076f0cd1e8182ed
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.16Fixed in: rhoai/odh-ml-pipelines-driver-rhel8:sha256:efd039012559786deb3c521a130886c265e88d635e08baace2e573a9df270134
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.16Fixed in: rhoai/odh-ml-pipelines-launcher-rhel8:sha256:27b113d96453c2054d4c965a963d2badba6daac235eddaf23234c76e87bcb069
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: libxml2-0:2.9.1-6.el7_9.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.16Fixed in: rhoai/odh-modelmesh-rhel8:sha256:c499a2c4a7860a1853adf3ebfbf154f3c03c478034a78566b82711373210af39
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.16Fixed in: rhoai/odh-modelmesh-runtime-adapter-rhel8:sha256:4a7599f8a866eb169c9a62885906adbf6df0417c0be15857df1eef20cd9b1be2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.16Fixed in: rhoai/odh-notebook-controller-rhel8:sha256:4c5ff3496b2a2a739939d94ee9dafc02b682100785d228dc2fde480fb597b7a5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.5.1Fixed in: rhosdt/opentelemetry-collector-rhel8:sha256:8b7455c14f26b80006568829343688b50ad1c563d339c35f70eb7d561499bc1c
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.5.1Fixed in: rhosdt/opentelemetry-rhel8-operator:sha256:ffd6b70068dd4d6bf7a835c0bbf5b934f26ff2b0f5755130dccb099340550083
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.5.1Fixed in: rhosdt/opentelemetry-target-allocator-rhel8:sha256:bf3aa3e5522cf90d82fbd34710e08448a93b88a9876c77415a1027f83a195a81
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift Network Observability 1.8.1Fixed in: network-observability/network-observability-rhel9-operator:sha256:5c284278b38c431f87b8ee743dabfd10ea24961dee76b7f8f3b3a84269a37993
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.16Fixed in: rhoai/odh-model-controller-rhel8:sha256:6cf74044ae8d5308a2dfe03fa5d81086c89302db7f4cdbe2f4174a1c48b77869
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: libxml2-0:2.9.7-19.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: libxml2-0:2.9.7-9.el8_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: libxml2-0:2.9.7-9.el8_4.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: libxml2-0:2.9.7-9.el8_4.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: libxml2-0:2.9.7-9.el8_4.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: libxml2-0:2.9.7-13.el8_6.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: libxml2-0:2.9.7-13.el8_6.8
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: libxml2

Vendor Advisories (4)

codesysllm-codesys-fe85e88fbae25bb9CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
esphomellm-esphome-ed450ce9fd6a7380CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
redhatCVE-2024-56171Important

libxml2: Use-After-Free in libxml2

Feb 18, 2025
microsoft2025-Feb/CVE-2024-56171Important

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.

Feb 11, 2025

References

seclists.org / fulldisclosure/2025/Apr/10
seclists.org / fulldisclosure/2025/Apr/11
seclists.org / fulldisclosure/2025/Apr/12
seclists.org / fulldisclosure/2025/Apr/13
seclists.org / fulldisclosure/2025/Apr/4
seclists.org / fulldisclosure/2025/Apr/5
seclists.org / fulldisclosure/2025/Apr/8
seclists.org / fulldisclosure/2025/Apr/9
lists.debian.org / debian-lts-announce/2025/02/msg00028.html
security.netapp.com / advisory/ntap-20250328-0010
Third Party Advisory
gitlab.gnome.org / GNOME/libxml2/-/issues/828
Issue Tracking