CVE-2025-24928

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
cpe:2.3:a:netapp:manageability_software_development_kit:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

History

16 Oct 2025, 19:34

Type Values Removed Values Added
CPE cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:manageability_software_development_kit:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
References () https://gitlab.gnome.org/GNOME/libxml2/-/issues/847 - () https://gitlab.gnome.org/GNOME/libxml2/-/issues/847 - Issue Tracking
References () https://issues.oss-fuzz.com/issues/392687022 - () https://issues.oss-fuzz.com/issues/392687022 - Issue Tracking
References () https://security.netapp.com/advisory/ntap-20250321-0006/ - () https://security.netapp.com/advisory/ntap-20250321-0006/ - Third Party Advisory
First Time Netapp hci Compute Node
Netapp h500s
Netapp h410c Firmware
Netapp h700s Firmware
Netapp active Iq Unified Manager
Netapp h410s Firmware
Netapp
Netapp ontap
Xmlsoft
Netapp h410c
Xmlsoft libxml2
Netapp h500s Firmware
Netapp h410s
Netapp solidfire \& Hci Management Node
Netapp h700s
Netapp h300s
Netapp h300s Firmware
Netapp manageability Software Development Kit

21 Mar 2025, 18:15

Type Values Removed Values Added
Summary
  • (es) LibXML2 antes de 2.12.10 y 2.13.x antes de 2.13.6 tiene un desbordamiento de búfer basado en pila en XMLSNPrintfelements en Valid.c. Para explotar esto, la validación de DTD debe ocurrir para un documento no confiable o DTD no confiable. Nota: Esto es similar a CVE-2017-9047.
References
  • () https://security.netapp.com/advisory/ntap-20250321-0006/ -

18 Feb 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-18 23:15

Updated : 2025-10-16 19:34


NVD link : CVE-2025-24928

Mitre link : CVE-2025-24928

CVE.ORG link : CVE-2025-24928


JSON object : View

Products Affected

netapp

  • h410s_firmware
  • h410c
  • hci_compute_node
  • h500s_firmware
  • h300s
  • h500s
  • h700s
  • solidfire_\&_hci_management_node
  • h410c_firmware
  • manageability_software_development_kit
  • h300s_firmware
  • h700s_firmware
  • active_iq_unified_manager
  • h410s
  • ontap

xmlsoft

  • libxml2
CWE
CWE-121

Stack-based Buffer Overflow