CVE Database
/

CVE-2024-8176

Back to search

CVE-2024-8176

Published: Mar 14, 2025

Modified: Apr 22, 2026

PUBLISHED

CVSS v3.1

7.5

HIGH

Description

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.

VendorProductVersions

Unknown

libexpat

affected
0 - < 2.7.0

Red Hat

Red Hat Enterprise Linux 10

unaffected
0:2.7.1-1.el10_0 - < *

Red Hat

Red Hat Enterprise Linux 8

unaffected
0:2.2.5-17.el8_10 - < *

Red Hat

Red Hat Enterprise Linux 8

unaffected
0:1.51.0-11.el8_10 - < *

Red Hat

Red Hat Enterprise Linux 8.2 Advanced Update Support

unaffected
0:2.2.10-1.el8_2 - < *

Red Hat

Red Hat Enterprise Linux 8.2 Advanced Update Support

unaffected
0:1.51.0-5.el8_2.2 - < *

Red Hat

Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support

unaffected
0:2.2.10-1.el8_4 - < *

Red Hat

Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support

unaffected
0:1.51.0-5.el8_4.2 - < *

Red Hat

Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

unaffected
0:2.2.10-1.el8_4 - < *

Red Hat

Red Hat Enterprise Linux 8.4 Telecommunications Update Service

unaffected
0:1.51.0-5.el8_4.2 - < *

Red Hat

Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions

unaffected
0:1.51.0-5.el8_4.2 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support

unaffected
0:2.2.10-1.el8_6 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support

unaffected
0:1.51.0-6.el8_6.1 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Telecommunications Update Service

unaffected
0:2.2.10-1.el8_6 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Telecommunications Update Service

unaffected
0:1.51.0-6.el8_6.1 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions

unaffected
0:2.2.10-1.el8_6 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions

unaffected
0:1.51.0-6.el8_6.1 - < *

Red Hat

Red Hat Enterprise Linux 8.8 Extended Update Support

unaffected
0:1.51.0-8.el8_8.1 - < *

Red Hat

Red Hat Enterprise Linux 8.8 Telecommunications Update Service

unaffected
0:2.2.10-1.el8_8 - < *

Red Hat

Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions

unaffected
0:2.2.10-1.el8_8 - < *

Red Hat

Red Hat Enterprise Linux 9

unaffected
0:2.5.0-3.el9_5.3 - < *

Red Hat

Red Hat Enterprise Linux 9

unaffected
0:2.5.0-5.el9_6 - < *

Red Hat

Red Hat Enterprise Linux 9

unaffected
0:2.5.0-3.el9_5.3 - < *

Red Hat

Red Hat Enterprise Linux 9

unaffected
0:2.5.0-5.el9_6 - < *

Red Hat

Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

unaffected
0:2.2.10-12.el9_0.4 - < *

Red Hat

Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

unaffected
0:2.5.0-1.el9_2.3 - < *

Red Hat

Red Hat Enterprise Linux 9.4 Extended Update Support

unaffected
0:2.5.0-2.el9_4.3 - < *

Red Hat

Red Hat JBoss Core Services 2.4.62.SP1

All versions

Red Hat

DevWorkspace Operator 0.33

unaffected
sha256:937e1dff95d06b971adee9aeb55e0e2e963b6b14594f30354bb9cdb039c081dd - < *

Red Hat

Red Hat Discovery 1.14

unaffected
sha256:ad1045aa0de937c3a6969ec377f7bfeda9a44ee434a954e8245e9840316ffc1c - < *

Red Hat

Red Hat Discovery 1.14

unaffected
sha256:492e412759cf0eedfa5b557f7b0865f8864f84d0ed75e11dc8d7a840837d9644 - < *

Red Hat

Red Hat Enterprise Linux 6

All versions

Red Hat

Red Hat Enterprise Linux 6

All versions

Red Hat

Red Hat Enterprise Linux 7

All versions

Red Hat

Red Hat Enterprise Linux 7

All versions

Red Hat

Red Hat Enterprise Linux 7

All versions

Red Hat

Red Hat Enterprise Linux 8

All versions

Red Hat

Red Hat Enterprise Linux 8

All versions

Red Hat

Red Hat Enterprise Linux 8

All versions

Red Hat

Red Hat Enterprise Linux 8

All versions

Red Hat

Red Hat Enterprise Linux 9

All versions

Red Hat

Red Hat Enterprise Linux 9

All versions

Red Hat

Red Hat Enterprise Linux 9

All versions

Red Hat

Red Hat Enterprise Linux 9

All versions

Red Hat

Red Hat OpenShift Container Platform 4

All versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

References

RHSA-2025:13681
vendor-advisory
x_refsource_REDHAT
RHSA-2025:22033
vendor-advisory
x_refsource_REDHAT
RHSA-2025:22034
vendor-advisory
x_refsource_REDHAT
RHSA-2025:22035
vendor-advisory
x_refsource_REDHAT
RHSA-2025:22607
vendor-advisory
x_refsource_REDHAT
RHSA-2025:22785
vendor-advisory
x_refsource_REDHAT
RHSA-2025:22842
vendor-advisory
x_refsource_REDHAT
RHSA-2025:22871
vendor-advisory
x_refsource_REDHAT
RHSA-2025:3531
vendor-advisory
x_refsource_REDHAT
RHSA-2025:3734
vendor-advisory
x_refsource_REDHAT
RHSA-2025:3913
vendor-advisory
x_refsource_REDHAT
RHSA-2025:4048
vendor-advisory
x_refsource_REDHAT
RHSA-2025:4446
vendor-advisory
x_refsource_REDHAT
RHSA-2025:4447
vendor-advisory
x_refsource_REDHAT
RHSA-2025:4448
vendor-advisory
x_refsource_REDHAT
RHSA-2025:4449
vendor-advisory
x_refsource_REDHAT
RHSA-2025:7444
vendor-advisory
x_refsource_REDHAT
RHSA-2025:7512
vendor-advisory
x_refsource_REDHAT
RHSA-2025:8385
vendor-advisory
x_refsource_REDHAT
RHBZ#2310137
issue-tracking
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now