A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Mar 2025 17:45:00 +0000
Sat, 15 Mar 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Fri, 14 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 14 Mar 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat | Libexpat: expat: improper restriction of xml entity expansion depth in libexpat |
First Time appeared |
Redhat
Redhat enterprise Linux Redhat jboss Core Services Redhat openshift |
|
CPEs | cpe:/a:redhat:jboss_core_services:1 cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
Vendors & Products |
Redhat
Redhat enterprise Linux Redhat jboss Core Services Redhat openshift |
|
References |
|
Fri, 14 Mar 2025 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage. | |
Title | libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat | |
Weaknesses | CWE-674 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published: 2025-03-14T08:19:48.962Z
Updated: 2025-03-17T16:50:07.393Z
Reserved: 2024-08-26T12:36:40.985Z
Link: CVE-2024-8176

Updated: 2025-03-17T16:50:07.393Z

Status : Awaiting Analysis
Published: 2025-03-14T09:15:14.157
Modified: 2025-03-17T17:15:36.167
Link: CVE-2024-8176
