Bug 2346416 (CVE-2024-56171) - CVE-2024-56171 libxml2: Use-After-Free in libxml2
Summary: CVE-2024-56171 libxml2: Use-After-Free in libxml2
Keywords:
Status: NEW
Alias: CVE-2024-56171
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2346505 2346506 2346507 2346508 2346510 2346511 2346512 2346514 2346515 2346516 2346509 2346513
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-02-18 23:01 UTC by OSIDB Bzimport
Modified: 2025-04-17 17:00 UTC (History)
20 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2025:2587 0 None None None 2025-03-10 23:31:34 UTC
Red Hat Product Errata RHBA-2025:2682 0 None None None 2025-03-12 14:24:55 UTC
Red Hat Product Errata RHBA-2025:2684 0 None None None 2025-03-12 14:21:16 UTC
Red Hat Product Errata RHBA-2025:2731 0 None None None 2025-03-13 11:01:06 UTC
Red Hat Product Errata RHBA-2025:2755 0 None None None 2025-03-13 13:33:05 UTC
Red Hat Product Errata RHBA-2025:2786 0 None None None 2025-03-13 14:25:27 UTC
Red Hat Product Errata RHBA-2025:2787 0 None None None 2025-03-13 14:24:46 UTC
Red Hat Product Errata RHBA-2025:2790 0 None None None 2025-03-13 14:45:17 UTC
Red Hat Product Errata RHBA-2025:2800 0 None None None 2025-03-13 16:03:56 UTC
Red Hat Product Errata RHBA-2025:2801 0 None None None 2025-03-13 15:59:08 UTC
Red Hat Product Errata RHBA-2025:2802 0 None None None 2025-03-13 15:58:40 UTC
Red Hat Product Errata RHBA-2025:2852 0 None None None 2025-03-17 00:13:44 UTC
Red Hat Product Errata RHBA-2025:2853 0 None None None 2025-03-17 00:23:18 UTC
Red Hat Product Errata RHBA-2025:2854 0 None None None 2025-03-17 00:32:14 UTC
Red Hat Product Errata RHBA-2025:2855 0 None None None 2025-03-17 00:31:27 UTC
Red Hat Product Errata RHBA-2025:2856 0 None None None 2025-03-17 00:32:26 UTC
Red Hat Product Errata RHBA-2025:2857 0 None None None 2025-03-17 00:17:54 UTC
Red Hat Product Errata RHBA-2025:2859 0 None None None 2025-03-17 00:39:39 UTC
Red Hat Product Errata RHBA-2025:2884 0 None None None 2025-03-17 09:43:18 UTC
Red Hat Product Errata RHBA-2025:2885 0 None None None 2025-03-17 10:05:41 UTC
Red Hat Product Errata RHBA-2025:2886 0 None None None 2025-03-17 10:00:32 UTC
Red Hat Product Errata RHBA-2025:2887 0 None None None 2025-03-17 08:42:24 UTC
Red Hat Product Errata RHBA-2025:2905 0 None None None 2025-03-17 10:04:48 UTC
Red Hat Product Errata RHBA-2025:2916 0 None None None 2025-03-17 13:18:36 UTC
Red Hat Product Errata RHBA-2025:2934 0 None None None 2025-03-17 13:55:26 UTC
Red Hat Product Errata RHBA-2025:2935 0 None None None 2025-03-17 14:08:41 UTC
Red Hat Product Errata RHBA-2025:2936 0 None None None 2025-03-17 14:02:38 UTC
Red Hat Product Errata RHBA-2025:2937 0 None None None 2025-03-17 14:09:26 UTC
Red Hat Product Errata RHBA-2025:2938 0 None None None 2025-03-17 14:23:42 UTC
Red Hat Product Errata RHBA-2025:2939 0 None None None 2025-03-17 14:27:44 UTC
Red Hat Product Errata RHBA-2025:2940 0 None None None 2025-03-17 14:25:12 UTC
Red Hat Product Errata RHBA-2025:2941 0 None None None 2025-03-17 14:26:45 UTC
Red Hat Product Errata RHBA-2025:2942 0 None None None 2025-03-17 14:25:23 UTC
Red Hat Product Errata RHBA-2025:2944 0 None None None 2025-03-17 14:55:57 UTC
Red Hat Product Errata RHBA-2025:2945 0 None None None 2025-03-17 15:00:34 UTC
Red Hat Product Errata RHBA-2025:2949 0 None None None 2025-03-17 15:34:07 UTC
Red Hat Product Errata RHBA-2025:2950 0 None None None 2025-03-17 15:36:21 UTC
Red Hat Product Errata RHBA-2025:2951 0 None None None 2025-03-17 15:36:09 UTC
Red Hat Product Errata RHBA-2025:2961 0 None None None 2025-03-17 17:59:31 UTC
Red Hat Product Errata RHBA-2025:3007 0 None None None 2025-03-18 12:20:29 UTC
Red Hat Product Errata RHBA-2025:3090 0 None None None 2025-03-20 15:22:56 UTC
Red Hat Product Errata RHBA-2025:3119 0 None None None 2025-03-24 17:04:16 UTC
Red Hat Product Errata RHBA-2025:3120 0 None None None 2025-03-24 17:46:43 UTC
Red Hat Product Errata RHBA-2025:3183 0 None None None 2025-03-25 20:27:05 UTC
Red Hat Product Errata RHBA-2025:3281 0 None None None 2025-03-26 16:40:11 UTC
Red Hat Product Errata RHBA-2025:3283 0 None None None 2025-03-26 17:54:06 UTC
Red Hat Product Errata RHBA-2025:3352 0 None None None 2025-03-27 17:56:04 UTC
Red Hat Product Errata RHBA-2025:3402 0 None None None 2025-03-31 13:56:12 UTC
Red Hat Product Errata RHBA-2025:3403 0 None None None 2025-03-31 13:57:15 UTC
Red Hat Product Errata RHBA-2025:3405 0 None None None 2025-03-31 14:14:30 UTC
Red Hat Product Errata RHBA-2025:3532 0 None None None 2025-04-02 14:39:19 UTC
Red Hat Product Errata RHBA-2025:3597 0 None None None 2025-04-03 19:28:41 UTC
Red Hat Product Errata RHBA-2025:3599 0 None None None 2025-04-03 21:18:41 UTC
Red Hat Product Errata RHBA-2025:3703 0 None None None 2025-04-08 18:39:13 UTC
Red Hat Product Errata RHBA-2025:3761 0 None None None 2025-04-09 15:25:16 UTC
Red Hat Product Errata RHBA-2025:3769 0 None None None 2025-04-09 20:07:44 UTC
Red Hat Product Errata RHBA-2025:3770 0 None None None 2025-04-09 20:01:45 UTC
Red Hat Product Errata RHBA-2025:3771 0 None None None 2025-04-09 22:52:53 UTC
Red Hat Product Errata RHBA-2025:3783 0 None None None 2025-04-10 07:18:58 UTC
Red Hat Product Errata RHBA-2025:3938 0 None None None 2025-04-16 06:51:08 UTC
Red Hat Product Errata RHBA-2025:4001 0 None None None 2025-04-17 17:00:22 UTC
Red Hat Product Errata RHSA-2025:2482 0 None None None 2025-03-10 05:39:08 UTC
Red Hat Product Errata RHSA-2025:2483 0 None None None 2025-03-10 05:51:21 UTC
Red Hat Product Errata RHSA-2025:2507 0 None None None 2025-03-10 13:09:17 UTC
Red Hat Product Errata RHSA-2025:2513 0 None None None 2025-03-10 14:14:35 UTC
Red Hat Product Errata RHSA-2025:2654 0 None None None 2025-03-11 10:10:38 UTC
Red Hat Product Errata RHSA-2025:2660 0 None None None 2025-03-11 13:19:21 UTC
Red Hat Product Errata RHSA-2025:2673 0 None None None 2025-03-12 00:14:21 UTC
Red Hat Product Errata RHSA-2025:2678 0 None None None 2025-03-12 11:25:53 UTC
Red Hat Product Errata RHSA-2025:2679 0 None None None 2025-03-12 11:34:07 UTC
Red Hat Product Errata RHSA-2025:2686 0 None None None 2025-03-12 15:45:11 UTC
Red Hat Product Errata RHSA-2025:2701 0 None None None 2025-03-20 07:01:45 UTC
Red Hat Product Errata RHSA-2025:3055 0 None None None 2025-03-26 13:09:01 UTC
Red Hat Product Errata RHSA-2025:3059 0 None None None 2025-03-26 21:50:21 UTC
Red Hat Product Errata RHSA-2025:3066 0 None None None 2025-03-25 06:59:18 UTC
Red Hat Product Errata RHSA-2025:3301 0 None None None 2025-04-03 00:22:40 UTC
Red Hat Product Errata RHSA-2025:3453 0 None None None 2025-04-02 17:07:04 UTC
Red Hat Product Errata RHSA-2025:3569 0 None None None 2025-04-09 20:55:45 UTC
Red Hat Product Errata RHSA-2025:3573 0 None None None 2025-04-10 21:37:34 UTC

Description OSIDB Bzimport 2025-02-18 23:01:48 UTC
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.

Comment 2 errata-xmlrpc 2025-03-10 05:39:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2025:2482 https://access.redhat.com/errata/RHSA-2025:2482

Comment 3 errata-xmlrpc 2025-03-10 05:51:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:2483 https://access.redhat.com/errata/RHSA-2025:2483

Comment 4 errata-xmlrpc 2025-03-10 13:09:15 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2025:2507 https://access.redhat.com/errata/RHSA-2025:2507

Comment 5 errata-xmlrpc 2025-03-10 14:14:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:2513 https://access.redhat.com/errata/RHSA-2025:2513

Comment 6 errata-xmlrpc 2025-03-11 10:10:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2025:2654 https://access.redhat.com/errata/RHSA-2025:2654

Comment 7 errata-xmlrpc 2025-03-11 13:19:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.4 Telecommunications Update Service

Via RHSA-2025:2660 https://access.redhat.com/errata/RHSA-2025:2660

Comment 8 errata-xmlrpc 2025-03-12 00:14:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2025:2673 https://access.redhat.com/errata/RHSA-2025:2673

Comment 9 errata-xmlrpc 2025-03-12 11:25:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:2678 https://access.redhat.com/errata/RHSA-2025:2678

Comment 10 errata-xmlrpc 2025-03-12 11:34:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:2679 https://access.redhat.com/errata/RHSA-2025:2679

Comment 11 errata-xmlrpc 2025-03-12 15:45:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:2686 https://access.redhat.com/errata/RHSA-2025:2686

Comment 12 errata-xmlrpc 2025-03-20 07:01:42 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.13

Via RHSA-2025:2701 https://access.redhat.com/errata/RHSA-2025:2701

Comment 13 errata-xmlrpc 2025-03-25 06:59:15 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.18

Via RHSA-2025:3066 https://access.redhat.com/errata/RHSA-2025:3066

Comment 14 errata-xmlrpc 2025-03-26 13:08:59 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.15

Via RHSA-2025:3055 https://access.redhat.com/errata/RHSA-2025:3055

Comment 15 errata-xmlrpc 2025-03-26 21:50:18 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.17

Via RHSA-2025:3059 https://access.redhat.com/errata/RHSA-2025:3059

Comment 16 errata-xmlrpc 2025-04-02 17:07:01 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Core Services

Via RHSA-2025:3453 https://access.redhat.com/errata/RHSA-2025:3453

Comment 17 errata-xmlrpc 2025-04-03 00:21:33 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.16

Via RHSA-2025:3301 https://access.redhat.com/errata/RHSA-2025:3301

Comment 19 errata-xmlrpc 2025-04-09 20:55:42 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.14

Via RHSA-2025:3569 https://access.redhat.com/errata/RHSA-2025:3569

Comment 20 errata-xmlrpc 2025-04-10 21:37:31 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.12

Via RHSA-2025:3573 https://access.redhat.com/errata/RHSA-2025:3573


Note You need to log in before you can comment on or make changes to this bug.