CVE-2024-8176

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.
CVSS

No CVSS.

Configurations

No configuration.

History

14 Aug 2025, 16:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:13681 -

02 Jun 2025, 15:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:8385 -

13 May 2025, 23:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:7444 -
  • () https://access.redhat.com/errata/RHSA-2025:7512 -

09 May 2025, 14:15

Type Values Removed Values Added
References
  • () https://www.kb.cert.org/vuls/id/760160 -

05 May 2025, 08:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:4448 -
  • () https://access.redhat.com/errata/RHSA-2025:4449 -
  • () https://access.redhat.com/errata/RHSA-2025:4446 -

05 May 2025, 03:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:4447 -

23 Apr 2025, 12:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:4048 -

15 Apr 2025, 17:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:3913 -

09 Apr 2025, 08:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:3734 -

02 Apr 2025, 15:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:3531 -

28 Mar 2025, 15:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250328-0009/ -

17 Mar 2025, 17:15

Type Values Removed Values Added
References
  • () https://ubuntu.com/security/CVE-2024-8176 -
  • () https://bugzilla.suse.com/show_bug.cgi?id=1239618 -
  • () https://security-tracker.debian.org/tracker/CVE-2024-8176 -
  • () https://blog.hartwork.org/posts/expat-2-7-0-released/ -
  • () https://gitlab.alpinelinux.org/alpine/aports/-/commit/d068c3ff36fc6f4789988a09c69b434db757db53 -
  • () https://github.com/libexpat/libexpat/blob/R_2_7_0/expat/Changes#L40-L52 -

15 Mar 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : unknown
References
  • () http://www.openwall.com/lists/oss-security/2025/03/15/1 -
CWE CWE-674

14 Mar 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-14 09:15

Updated : 2025-08-14 16:15


NVD link : CVE-2024-8176

Mitre link : CVE-2024-8176


JSON object : View

Products Affected

No product.

CWE

No CWE.