CVE-2024-50602

An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:windows_host_utilities:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*

Configuration 7 (hide)

cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*

History

15 Oct 2025, 17:54

Type Values Removed Values Added
First Time Netapp hci Compute Node
Netapp h500s
Debian
Netapp h410c Firmware
Netapp active Iq Unified Manager
Netapp h700s Firmware
Netapp
Netapp h410s Firmware
Netapp h410c
Netapp h500s Firmware
Netapp h410s
Netapp windows Host Utilities
Libexpat Project libexpat
Libexpat Project
Netapp solidfire \& Hci Management Node
Netapp h700s
Netapp h300s
Netapp solidfire \& Hci Storage Node
Netapp h300s Firmware
Debian debian Linux
CPE cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:windows_host_utilities:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
References () https://github.com/libexpat/libexpat/pull/915 - () https://github.com/libexpat/libexpat/pull/915 - Issue Tracking
References () https://lists.debian.org/debian-lts-announce/2025/04/msg00040.html - () https://lists.debian.org/debian-lts-announce/2025/04/msg00040.html - Mailing List, Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20250404-0008/ - () https://security.netapp.com/advisory/ntap-20250404-0008/ - Third Party Advisory

30 Apr 2025, 20:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/04/msg00040.html -

04 Apr 2025, 23:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250404-0008/ -

Information

Published : 2024-10-27 05:15

Updated : 2025-10-15 17:54


NVD link : CVE-2024-50602

Mitre link : CVE-2024-50602

CVE.ORG link : CVE-2024-50602


JSON object : View

Products Affected

netapp

  • h410s_firmware
  • h410c
  • hci_compute_node
  • h500s_firmware
  • h300s
  • h500s
  • h700s
  • windows_host_utilities
  • solidfire_\&_hci_management_node
  • h300s_firmware
  • h410c_firmware
  • h700s_firmware
  • active_iq_unified_manager
  • solidfire_\&_hci_storage_node
  • h410s

libexpat_project

  • libexpat

debian

  • debian_linux
CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions