FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

libxml2 -- Use After Free

Affected packages
libxml2 < 2.13.6

Details

VuXML ID bd2af307-3e50-11f0-95d4-00a098b42aeb
Discovery 2025-02-18
Entry 2025-05-31

cve@mitre.org reports:

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.

References

CVE Name CVE-2024-56171
URL https://nvd.nist.gov/vuln/detail/CVE-2024-56171