Red Hat released Important security updates for libxml2 to remediate CVE-2024-56171, a use-after-free in XML Schema identity-constraint validation, and CVE-2025-24928, a stack-based buffer overflow in xmlSnprintfElements() during DTD validation. Both flaws affect libxml2 releases before 2.12.10 and 2.13.x before 2.13.6; exploitation requires processing crafted XML documents, schemas, or DTDs through vulnerable validation paths.
Advisories include RHSA-2025:2673 for RHEL 7 Extended Lifecycle Support, providing libxml2-2.9.1-6.el7_9.9, and RHSA-2025:2660 for specified RHEL 8.4 ELL, AUS, TUS, and SAP support channels, providing libxml2-2.9.7-9.el8_4.5. OpenShift Container Platform 4.15.48 also remediates both issues through updated container images; organizations should apply the relevant RHEL or OpenShift update across supported architectures and restrict validation of untrusted XML content until patching is complete.

See affected versions and whether adversaries are exploiting it.
20 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2025:9895 for Red Hat Service Interconnect 1.4 LTS on RHEL 8 and RHEL 9 x86_64. The Important advisory remediates libxml2 CVE-2024-56171 and CVE-2025-24928, as well as OpenSSL CVE-2024-12797 and other vulnerabilities.
Red Hat issued Important advisory RHSA-2025:3780 and released OpenShift Container Platform 4.13.57 for RHEL 8 and 9 deployments. The update provided packages and container images fixing libxml2 CVE-2025-24928 and GRUB2 out-of-bounds write CVE-2025-0624.
Red Hat issued Important advisory RHSA-2025:3569 and released OpenShift Container Platform 4.14.50 for RHEL 8 and 9 across x86_64, s390x, ppc64le, and aarch64. The update fixes libxml2 CVE-2024-56171 and CVE-2025-24928, as well as golang-jwt/jwt excessive-memory-allocation vulnerability CVE-2025-30204.
Red Hat issued Important advisory RHSA-2025:3453 for JBoss Core Services Apache HTTP Server 2.4.62, replacing version 2.4.57 Service Pack 6. The update addresses seven vulnerabilities, including libxml2 CVE-2024-56171 and CVE-2025-24928, as well as flaws in Expat, Apache HTTP Server, mod_http2, and OpenSSL.
Red Hat issued Important advisory RHSA-2025:3297 for OpenShift Container Platform 4.17.23, providing updated images and packages for RHEL 8 and 9 deployments. The release fixes libxml2 CVE-2025-24928, GRUB2 out-of-bounds write CVE-2025-0624, and CRI-O cross-namespace checkpoint-restore issue CVE-2024-8676.
Red Hat issued Important advisory RHSA-2025:3059 for OpenShift Container Platform 4.17.22. The release supplied updated images and packages addressing libxml2 CVE-2024-56171 and Go JOSE parsing denial-of-service vulnerability CVE-2025-27144.
Red Hat issued Important advisory RHSA-2025:3055 and released OpenShift Container Platform 4.15.48 container images. The release remediated CVE-2024-56171 and CVE-2025-24928, alongside the Linux kernel USB-audio flaw CVE-2024-53197.
Red Hat issued Important advisory RHSA-2025:3066 for OpenShift Container Platform 4.18.6, supplying updated container images and packages for RHEL 8 and 9 across x86_64, s390x, ppc64le, and aarch64. The release remediates libxml2 use-after-free CVE-2024-56171 and Go JOSE parsing denial-of-service vulnerability CVE-2025-27144.
Red Hat issued Important advisory RHSA-2025:2678 for RHEL 9.4 Extended Update Support and related lifecycle channels, supplying libxml2-2.9.13-9.el9_4. The update fixes CVE-2022-49043, CVE-2024-56171, and CVE-2025-24928.
Red Hat published Important advisory RHSA-2025:2686 for standard RHEL 8 and RHEL 8.10 Extended Life Cycle deployments, fixing CVE-2024-56171 and CVE-2025-24928. The update provided libxml2 2.9.7-19.el8_10 packages for x86_64, s390x, ppc64le, and aarch64.
Red Hat published RHSA-2025:2660, an Important update for specified RHEL 8.4 support offerings, remediating CVE-2024-56171 and CVE-2025-24928. The advisory provided libxml2 version 2.9.7-9.el8_4.5 for affected x86_64 and ppc64le deployments.
Red Hat issued Important advisory RHSA-2025:2654 for Red Hat Enterprise Linux Server Advanced Update Support 8.2, fixing libxml2 CVE-2024-56171 and CVE-2025-24928. The advisory supplied libxml2-2.9.7-9.el8_2.1 packages for affected x86_64 and i686 systems.
Red Hat issued RHSA-2025:2673 for RHEL 7 Extended Lifecycle Support, fixing CVE-2024-56171 and CVE-2025-24928. The update supplied libxml2 version 2.9.1-6.el7_9.9 packages for x86_64, s390x, ppc64, and ppc64le systems.
Red Hat issued Important advisory RHSA-2025:2507 for RHEL 8.8 extended-support offerings, supplying libxml2 2.9.7-16.el8_8.7 packages. The update remediates CVE-2022-49043, CVE-2024-56171, and CVE-2025-24928 across supported x86_64, s390x, ppc64le, and aarch64 variants.
Red Hat issued Important advisory RHSA-2025:2513 for multiple RHEL 8.6 support offerings, including Extended Life Cycle Long Life, Advanced Update Support, Telecommunications Update Service, and SAP Update Services. The update supplied libxml2 2.9.7-13.el8_6.8 packages for x86_64 and ppc64le, remediating CVE-2024-56171 and CVE-2025-24928.
Red Hat issued Important advisory RHSA-2025:2482 for RHEL 9.2 Extended Update Support, AUS, SAP Update Services, and Extended Life Cycle deployments. The update supplied libxml2 2.9.13-3.el9_2.6 for x86_64, aarch64, ppc64le, and s390x, remediating CVE-2024-56171 and CVE-2025-24928.
Red Hat issued Important advisory RHSA-2025:2483 for RHEL 9.0 Update Services for SAP Solutions. The update supplies libxml2 2.9.13-1.el9_0.4 for ppc64le, x86_64, aarch64, and s390x, remediating CVE-2024-56171 and CVE-2025-24928.
Red Hat documented an out-of-bounds write in GRUB's grub_net_search_config_file() during network boot, where an attacker-controlled environment variable is copied with grub_strcpy() into an undersized buffer. Exploitation from the boot-information network segment could permit remote code execution and potentially bypass Secure Boot protections.
A stack-based buffer overflow in libxml2's xmlSnprintfElements function affects versions before 2.12.10 and versions 2.13.0 through 2.13.5. Exploitation requires DTD validation of an untrusted XML document or DTD.
libxml2 versions before 2.12.10 and 2.13.x before 2.13.6 contain a use-after-free flaw in XML Schema validation functions xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables. It can be triggered by validating crafted XML documents or schemas with certain identity constraints.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
21 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.