{
  "threat_severity" : "Moderate",
  "public_date" : "2025-03-13T13:51:54Z",
  "bugzilla" : {
    "description" : "libexpat: expat: Improper Restriction of XML Entity Expansion Depth in libexpat",
    "id" : "2310137",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2310137"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-674",
  "details" : [ "A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.", "A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage." ],
  "statement" : "All supported Red Hat offerings are built with the compilation flag (-fstack-clash-protection) which reduces the impact to Moderate. This build configuration blocks the possibility of an attacker gaining arbitrary code execution even if a stack-clash vulnerability, like this one, could be exploited.\nThis vulnerability is rated Moderate because Red Hat builds use the `-fstack-clash-protection` compiler flag, which mitigates the risk of arbitrary code execution from stack overflows. While the flaw allows a crash via uncontrolled recursion in XML parsing, the hardened stack layout prevents reliable memory corruption, limiting the impact to a Denial of Service (DoS) scenario.",
  "acknowledgement" : "This issue was discovered by Jann Horn (Google Project Zero), Sandipan Roy (Red Hat), Sebastian Pipping (libexpat), and Tomas Korbar (Red Hat).",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2025-05-13T00:00:00Z",
    "advisory" : "RHSA-2025:7512",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.0",
    "package" : "expat-0:2.7.1-1.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3913",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8",
    "package" : "expat-0:2.2.5-17.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2025-04-23T00:00:00Z",
    "advisory" : "RHSA-2025:4048",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8",
    "package" : "xmlrpc-c-0:1.51.0-11.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.2 Advanced Update Support",
    "release_date" : "2025-12-09T00:00:00Z",
    "advisory" : "RHSA-2025:22871",
    "cpe" : "cpe:/o:redhat:rhel_aus:8.2",
    "package" : "expat-0:2.2.10-1.el8_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.2 Advanced Update Support",
    "release_date" : "2025-05-05T00:00:00Z",
    "advisory" : "RHSA-2025:4447",
    "cpe" : "cpe:/o:redhat:rhel_aus:8.2",
    "package" : "xmlrpc-c-0:1.51.0-5.el8_2.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
    "release_date" : "2025-12-04T00:00:00Z",
    "advisory" : "RHSA-2025:22785",
    "cpe" : "cpe:/o:redhat:rhel_aus:8.4",
    "package" : "expat-0:2.2.10-1.el8_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
    "release_date" : "2025-05-05T00:00:00Z",
    "advisory" : "RHSA-2025:4448",
    "cpe" : "cpe:/o:redhat:rhel_aus:8.4",
    "package" : "xmlrpc-c-0:1.51.0-5.el8_4.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
    "release_date" : "2025-12-04T00:00:00Z",
    "advisory" : "RHSA-2025:22785",
    "cpe" : "cpe:/o:redhat:rhel_eus_long_life:8.4",
    "package" : "expat-0:2.2.10-1.el8_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Telecommunications Update Service",
    "release_date" : "2025-05-05T00:00:00Z",
    "advisory" : "RHSA-2025:4448",
    "cpe" : "cpe:/o:redhat:rhel_tus:8.4",
    "package" : "xmlrpc-c-0:1.51.0-5.el8_4.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions",
    "release_date" : "2025-05-05T00:00:00Z",
    "advisory" : "RHSA-2025:4448",
    "cpe" : "cpe:/o:redhat:rhel_e4s:8.4",
    "package" : "xmlrpc-c-0:1.51.0-5.el8_4.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
    "release_date" : "2025-12-09T00:00:00Z",
    "advisory" : "RHSA-2025:22842",
    "cpe" : "cpe:/o:redhat:rhel_aus:8.6",
    "package" : "expat-0:2.2.10-1.el8_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
    "release_date" : "2025-05-05T00:00:00Z",
    "advisory" : "RHSA-2025:4449",
    "cpe" : "cpe:/o:redhat:rhel_aus:8.6",
    "package" : "xmlrpc-c-0:1.51.0-6.el8_6.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
    "release_date" : "2025-12-09T00:00:00Z",
    "advisory" : "RHSA-2025:22842",
    "cpe" : "cpe:/o:redhat:rhel_tus:8.6",
    "package" : "expat-0:2.2.10-1.el8_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
    "release_date" : "2025-05-05T00:00:00Z",
    "advisory" : "RHSA-2025:4449",
    "cpe" : "cpe:/o:redhat:rhel_tus:8.6",
    "package" : "xmlrpc-c-0:1.51.0-6.el8_6.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
    "release_date" : "2025-12-09T00:00:00Z",
    "advisory" : "RHSA-2025:22842",
    "cpe" : "cpe:/o:redhat:rhel_e4s:8.6",
    "package" : "expat-0:2.2.10-1.el8_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
    "release_date" : "2025-05-05T00:00:00Z",
    "advisory" : "RHSA-2025:4449",
    "cpe" : "cpe:/o:redhat:rhel_e4s:8.6",
    "package" : "xmlrpc-c-0:1.51.0-6.el8_6.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Extended Update Support",
    "release_date" : "2025-05-05T00:00:00Z",
    "advisory" : "RHSA-2025:4446",
    "cpe" : "cpe:/o:redhat:rhel_eus:8.8",
    "package" : "xmlrpc-c-0:1.51.0-8.el8_8.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2025-12-02T00:00:00Z",
    "advisory" : "RHSA-2025:22607",
    "cpe" : "cpe:/o:redhat:rhel_tus:8.8",
    "package" : "expat-0:2.2.10-1.el8_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2025-12-02T00:00:00Z",
    "advisory" : "RHSA-2025:22607",
    "cpe" : "cpe:/o:redhat:rhel_e4s:8.8",
    "package" : "expat-0:2.2.10-1.el8_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2025-04-02T00:00:00Z",
    "advisory" : "RHSA-2025:3531",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "expat-0:2.5.0-3.el9_5.3"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2025-05-13T00:00:00Z",
    "advisory" : "RHSA-2025:7444",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "expat-0:2.5.0-5.el9_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2025-04-02T00:00:00Z",
    "advisory" : "RHSA-2025:3531",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "expat-0:2.5.0-3.el9_5.3"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2025-05-13T00:00:00Z",
    "advisory" : "RHSA-2025:7444",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "expat-0:2.5.0-5.el9_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
    "release_date" : "2025-11-25T00:00:00Z",
    "advisory" : "RHSA-2025:22035",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.0",
    "package" : "expat-0:2.2.10-12.el9_0.4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2025-11-25T00:00:00Z",
    "advisory" : "RHSA-2025:22034",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "expat-0:2.5.0-1.el9_2.3"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Extended Update Support",
    "release_date" : "2025-11-25T00:00:00Z",
    "advisory" : "RHSA-2025:22033",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.4",
    "package" : "expat-0:2.5.0-2.el9_4.3"
  }, {
    "product_name" : "Red Hat JBoss Core Services 2.4.62.SP1",
    "release_date" : "2025-08-14T00:00:00Z",
    "advisory" : "RHSA-2025:13681",
    "cpe" : "cpe:/a:redhat:jboss_core_services:1",
    "package" : "expat"
  }, {
    "product_name" : "DevWorkspace Operator 0.33",
    "release_date" : "2025-04-09T00:00:00Z",
    "advisory" : "RHSA-2025:3734",
    "cpe" : "cpe:/a:redhat:devworkspace:0.33::el9",
    "package" : "devworkspace/devworkspace-project-clone-rhel9:sha256:937e1dff95d06b971adee9aeb55e0e2e963b6b14594f30354bb9cdb039c081dd"
  }, {
    "product_name" : "Red Hat Discovery 1.14",
    "release_date" : "2025-06-02T00:00:00Z",
    "advisory" : "RHSA-2025:8385",
    "cpe" : "cpe:/a:redhat:discovery:1.14::el9",
    "package" : "discovery/discovery-server-rhel9:sha256:ad1045aa0de937c3a6969ec377f7bfeda9a44ee434a954e8245e9840316ffc1c"
  }, {
    "product_name" : "Red Hat Discovery 1.14",
    "release_date" : "2025-06-02T00:00:00Z",
    "advisory" : "RHSA-2025:8385",
    "cpe" : "cpe:/a:redhat:discovery:1.14::el9",
    "package" : "discovery/discovery-ui-rhel9:sha256:492e412759cf0eedfa5b557f7b0865f8864f84d0ed75e11dc8d7a840837d9644"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "compat-expat1",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "expat",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Out of support scope",
    "package_name" : "expat",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Out of support scope",
    "package_name" : "firefox",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Out of support scope",
    "package_name" : "thunderbird",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Will not fix",
    "package_name" : "firefox",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "lua-expat",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Affected",
    "package_name" : "mingw-expat",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Will not fix",
    "package_name" : "thunderbird",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Will not fix",
    "package_name" : "firefox",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Will not fix",
    "package_name" : "firefox:flatpak/firefox",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Will not fix",
    "package_name" : "thunderbird",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Will not fix",
    "package_name" : "thunderbird:flatpak/thunderbird",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Will not fix",
    "package_name" : "rhcos",
    "cpe" : "cpe:/a:redhat:openshift:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2024-8176\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-8176\nhttps://github.com/libexpat/libexpat/issues/893\nhttps://github.com/libexpat/libexpat/pull/973" ],
  "name" : "CVE-2024-8176",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}