CRITICAL 9.1 Microsoft
CVE-2024-40896
In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.
Microsoft Security Update 2024-Dec: In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.
Affected Products
- azl3 libxml2 2.11.5-2 on Azure Linux 3.0
- azl3 libxml2 2.11.5-5 on Azure Linux 3.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-40896
- https://nvd.nist.gov/vuln/detail/CVE-2024-40896
This critical severity vulnerability with a CVSS score of 9.1 was published on 2024-12-10 via Microsoft. Affected: azl3 libxml2 2.11.5-2 on Azure Linux 3.0, azl3 libxml2 2.11.5-5 on Azure Linux 3.0.
Risk Timeline
CVE Disclosed2024-12-10 · 657 days ago
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2024-40896NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2024-40896Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2024-56719 | net: stmmac: fix TSO DMA API usage causing oops | CRITICAL | 10.0 |
| CVE-2026-44210 | Kata Containers have VM Escape via virtiofsd Argument Injection through Default- | CRITICAL | 9.9 |
| CVE-2026-78030 | DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_ty | CRITICAL | 9.8 |
| CVE-2026-85504 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujits | CRITICAL | 9.8 |
| CVE-2026-85506 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_del | CRITICAL | 9.8 |
| CVE-2026-85507 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_ | CRITICAL | 9.8 |
vulnfeed aggregates 13625 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.